forge: external forge accounts live in swarm bao; the agent fetches them itself
An operator now links an agent's external forge account (label, base URL, token) in the swarm UI. swarm-controller stores it at swarm/agents/<agent>/forge/<label>. There is no index: the store's listing of the agent's forge/ directory is the set of accounts. In the agent, hive-agent-forge-accounts (oneshot + 2-minute timer, as the agent user, under its own store certificate) lists swarm/agents/<agent>/forge/ with the `list` #4866 grants an agent on its own metadata subtree, reads each account, and writes <state>/forge-<label>-token and forge-<label>.json in the names and shape hive-forge -f already reads. An empty listing (a 404, which `bao kv list -format=json` answers with `{}` and an empty stderr) is zero accounts; a denial or an unreachable store fails the unit. It never deletes: files for labels not listed, including ones the hive wrote, stay as they are. Removed: the dashboard FORGES tab (credentials.js/html section and its CSS), hive-c0re's extra_forges.rs and its routes, priv_client's extra-forge calls, and hive-priv's WriteAgentExtraForgeAccount / DeleteAgentExtraForgeAccount with their helpers. The GITHUB tab and WriteAgentGithubToken stay. Also: persistence.md's matrix avatar note names the exit-75 restart on a changed account listing, not the dashboard, as what brings a linked account up. Refs #4348
This commit is contained in:
parent
97fb76ce99
commit
2c7e586f47
27 changed files with 815 additions and 748 deletions
|
|
@ -494,43 +494,6 @@ pub enum PrivRequest {
|
|||
token: String,
|
||||
},
|
||||
|
||||
/// Write a per-agent account for an external, dashboard-declared forge:
|
||||
/// the access token to
|
||||
/// `AGENT_STATE_ROOT/<agent_name>/state/forge-<label>-token` (0600) and
|
||||
/// a `forge-<label>.json` sidecar (`{"base_url": <base_url>}`, 0600) so
|
||||
/// the base URL survives without any host-side nix config — the whole
|
||||
/// account (label + URL + token) is operator-entered on the dashboard.
|
||||
///
|
||||
/// `label` MUST be validated as a plain identifier before it goes into
|
||||
/// the filename — a crafted label could otherwise traverse out of the
|
||||
/// state dir. Same write semantics as `WriteAgentGithubToken` — validates
|
||||
/// `agent_name`, creates the state dir if absent, writes both files 0600,
|
||||
/// chowns to the agent.
|
||||
WriteAgentExtraForgeAccount {
|
||||
/// Logical agent name (validated by `validate_agent_name`).
|
||||
agent_name: String,
|
||||
/// Dashboard-chosen label for this external forge. Validated as a
|
||||
/// plain identifier before use.
|
||||
label: String,
|
||||
/// Base HTTP(S) URL of the external forge, operator-entered on the
|
||||
/// dashboard (no host-side config).
|
||||
base_url: String,
|
||||
/// Token value. hive-priv appends a trailing newline before writing.
|
||||
token: String,
|
||||
},
|
||||
|
||||
/// Remove a previously-written `forge-<label>-token` + `forge-<label>.
|
||||
/// json` from an agent's state dir — the revoke half of
|
||||
/// `WriteAgentExtraForgeAccount`. Missing files are not an error
|
||||
/// (idempotent revoke).
|
||||
DeleteAgentExtraForgeAccount {
|
||||
/// Logical agent name (validated by `validate_agent_name`).
|
||||
agent_name: String,
|
||||
/// The forge label to revoke. Validated as a plain identifier
|
||||
/// before use.
|
||||
label: String,
|
||||
},
|
||||
|
||||
/// Register the hive-ci Forgejo Actions runner: write the registration
|
||||
/// token to the host-side `/run/hive-ci/runner-token` env-file (root-owned,
|
||||
/// bind-mounted read-only into the container) as `TOKEN=<token>`, then
|
||||
|
|
|
|||
Loading…
Reference in a new issue