Watch
0
0
Fork
You've already forked hyperhive
0

forge: external forge accounts live in swarm bao; the agent fetches them itself

An operator now links an agent's external forge account (label, base URL,
token) in the swarm UI. swarm-controller stores it at
swarm/agents/<agent>/forge/<label>. There is no index: the store's
listing of the agent's forge/ directory is the set of accounts.

In the agent, hive-agent-forge-accounts (oneshot + 2-minute timer, as
the agent user, under its own store certificate) lists
swarm/agents/<agent>/forge/ with the `list` #4866 grants an agent on its
own metadata subtree, reads each account, and writes
<state>/forge-<label>-token and forge-<label>.json in the names and shape
hive-forge -f already reads. An empty listing (a 404, which `bao kv list
-format=json` answers with `{}` and an empty stderr) is zero accounts; a
denial or an unreachable store fails the unit. It never deletes: files
for labels not listed, including ones the hive wrote, stay as they are.

Removed: the dashboard FORGES tab (credentials.js/html section and its
CSS), hive-c0re's extra_forges.rs and its routes, priv_client's
extra-forge calls, and hive-priv's WriteAgentExtraForgeAccount /
DeleteAgentExtraForgeAccount with their helpers. The GITHUB tab and
WriteAgentGithubToken stay.

Also: persistence.md's matrix avatar note names the exit-75 restart on a
changed account listing, not the dashboard, as what brings a linked
account up.

Refs #4348
This commit is contained in:
atlas 2026-10-01 17:50:24 +02:00
commit 2c7e586f47
27 changed files with 815 additions and 748 deletions

View file

@ -388,37 +388,6 @@ pub async fn write_agent_github_token(agent_name: &str, token: &str) -> Result<(
.await?)
}
/// Write a per-agent account for a dashboard-declared external forge —
/// label + base URL + token — to `<state>/forge-<label>-token` +
/// `<state>/forge-<label>.json` via hive-priv. Entirely dashboard-
/// provisioned, no host-side nix config; `label` is validated root-side as
/// a plain identifier before it reaches the filename.
pub async fn write_agent_extra_forge_account(
agent_name: &str,
label: &str,
base_url: &str,
token: &str,
) -> Result<()> {
ok(call(&PrivRequest::WriteAgentExtraForgeAccount {
agent_name: agent_name.to_owned(),
label: label.to_owned(),
base_url: base_url.to_owned(),
token: token.to_owned(),
})
.await?)
}
/// Remove a previously-added extra-forge account — the counterpart of
/// [`write_agent_extra_forge_account`]. Idempotent: missing files are not
/// an error.
pub async fn delete_agent_extra_forge_account(agent_name: &str, label: &str) -> Result<()> {
ok(call(&PrivRequest::DeleteAgentExtraForgeAccount {
agent_name: agent_name.to_owned(),
label: label.to_owned(),
})
.await?)
}
/// Register the hive-ci Forgejo Actions runner: hand the freshly-minted
/// registration token to hive-priv, which writes it to the host-side
/// `/run/hive-ci/runner-token` env-file and restarts the in-container runner.