forge: external forge accounts live in swarm bao; the agent fetches them itself
An operator now links an agent's external forge account (label, base URL, token) in the swarm UI. swarm-controller stores it at swarm/agents/<agent>/forge/<label>. There is no index: the store's listing of the agent's forge/ directory is the set of accounts. In the agent, hive-agent-forge-accounts (oneshot + 2-minute timer, as the agent user, under its own store certificate) lists swarm/agents/<agent>/forge/ with the `list` #4866 grants an agent on its own metadata subtree, reads each account, and writes <state>/forge-<label>-token and forge-<label>.json in the names and shape hive-forge -f already reads. An empty listing (a 404, which `bao kv list -format=json` answers with `{}` and an empty stderr) is zero accounts; a denial or an unreachable store fails the unit. It never deletes: files for labels not listed, including ones the hive wrote, stay as they are. Removed: the dashboard FORGES tab (credentials.js/html section and its CSS), hive-c0re's extra_forges.rs and its routes, priv_client's extra-forge calls, and hive-priv's WriteAgentExtraForgeAccount / DeleteAgentExtraForgeAccount with their helpers. The GITHUB tab and WriteAgentGithubToken stay. Also: persistence.md's matrix avatar note names the exit-75 restart on a changed account listing, not the dashboard, as what brings a linked account up. Refs #4348
This commit is contained in:
parent
97fb76ce99
commit
2c7e586f47
27 changed files with 815 additions and 748 deletions
|
|
@ -46,6 +46,7 @@ in
|
|||
./dashboard-links.nix
|
||||
./docs.nix
|
||||
./forge.nix
|
||||
./forge-accounts.nix
|
||||
./forge-token.nix
|
||||
./frontend.nix
|
||||
./github.nix
|
||||
|
|
|
|||
191
nix/agent-modules/forge-accounts.nix
Normal file
191
nix/agent-modules/forge-accounts.nix
Normal file
|
|
@ -0,0 +1,191 @@
|
|||
# This agent's accounts on external forges, fetched from the swarm secret store
|
||||
# by the agent itself, into the files `hive-forge -f <label>` reads.
|
||||
#
|
||||
# An operator links an account in the swarm UI; `swarm-controller` stores it at
|
||||
# `swarm/agents/<agent>/forge/<label>` (`swarm_secret_client::forge`). The
|
||||
# agent's grant lists and reads its own subtree, so this unit lists
|
||||
# `swarm/agents/<agent>/forge/`, reads each account, and writes
|
||||
# `<state>/forge-<label>-token` and `<state>/forge-<label>.json`
|
||||
# (`{"base_url":…}`), the two files `hive-forge`'s `resolve_credentials` reads.
|
||||
#
|
||||
# It never deletes. A `forge-<label>` pair for a label not listed is left
|
||||
# as it is, whoever wrote it, and so is the pair of a label whose read fails.
|
||||
# A file is replaced by rename, and only when its bytes changed.
|
||||
{
|
||||
pkgs,
|
||||
lib,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
let
|
||||
cfg = config.services.hyperhive.agent.bao;
|
||||
|
||||
agentName = config.services.hyperhive.agent.user.name;
|
||||
stateDir = "/agents/${agentName}/state";
|
||||
|
||||
# The same three ids ./bao.nix and ./forge-token.nix load.
|
||||
certCredential = "hive-agent-bao-cert";
|
||||
keyCredential = "hive-agent-bao-key";
|
||||
serverCaCredential = "hive-agent-bao-server-ca";
|
||||
|
||||
unitName = "hive-agent-forge-accounts";
|
||||
|
||||
# The nix half of `swarm_secret_client::forge::accounts_dir` plus
|
||||
# `path::MOUNT`.
|
||||
accountsDir = "secret/swarm/agents/${agentName}/forge";
|
||||
|
||||
runtimeDir = unitName;
|
||||
# The store's whole answer for one account, token included: kept in the
|
||||
# unit's own `0700` directory, never in the state dir.
|
||||
rawFile = "/run/${runtimeDir}/account.json";
|
||||
listFile = "/run/${runtimeDir}/list.json";
|
||||
errFile = "/run/${runtimeDir}/bao.err";
|
||||
|
||||
configured = cfg.addr != null;
|
||||
|
||||
storeRetry = import ../host-modules/lib/store-retry.nix { };
|
||||
in
|
||||
{
|
||||
config = lib.mkIf configured {
|
||||
systemd.services.${unitName} = {
|
||||
description = "fetch this agent's external forge accounts from the secret store";
|
||||
after = [
|
||||
"network.target"
|
||||
"hive-agent-bao-identity.service"
|
||||
];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
path = [
|
||||
pkgs.openbao
|
||||
pkgs.coreutils
|
||||
pkgs.diffutils
|
||||
pkgs.jq
|
||||
];
|
||||
# ../host-modules/lib/store-retry.nix.
|
||||
inherit (storeRetry) startLimitBurst startLimitIntervalSec;
|
||||
serviceConfig = storeRetry.serviceConfig // {
|
||||
Type = "oneshot";
|
||||
# Not `RemainAfterExit`, so the timer below can start it again.
|
||||
RemainAfterExit = false;
|
||||
TimeoutStartSec = 60;
|
||||
User = agentName;
|
||||
Group = agentName;
|
||||
RuntimeDirectory = runtimeDir;
|
||||
RuntimeDirectoryMode = "0700";
|
||||
# `0600`, the mode the files in the state dir have always had.
|
||||
UMask = "0077";
|
||||
LoadCredential = [
|
||||
certCredential
|
||||
keyCredential
|
||||
serverCaCredential
|
||||
];
|
||||
};
|
||||
environment = {
|
||||
BAO_ADDR = cfg.addr;
|
||||
BAO_CLIENT_CERT = "%d/${certCredential}";
|
||||
BAO_CLIENT_KEY = "%d/${keyCredential}";
|
||||
};
|
||||
script = ''
|
||||
set -euo pipefail
|
||||
|
||||
# No identity delivered: ./bao.nix's check reports that.
|
||||
for id in ${lib.escapeShellArg certCredential} ${lib.escapeShellArg keyCredential}; do
|
||||
if [ ! -s "$CREDENTIALS_DIRECTORY/$id" ]; then
|
||||
echo "this agent has no store identity, so it cannot fetch its external forge accounts." >&2
|
||||
exit 0
|
||||
fi
|
||||
done
|
||||
|
||||
if [ -s "$CREDENTIALS_DIRECTORY/${serverCaCredential}" ]; then
|
||||
export BAO_CACERT="$CREDENTIALS_DIRECTORY/${serverCaCredential}"
|
||||
fi
|
||||
|
||||
err=${lib.escapeShellArg errFile}
|
||||
raw=${lib.escapeShellArg rawFile}
|
||||
list=${lib.escapeShellArg listFile}
|
||||
trap 'rm -f "$err" "$raw" "$list"' EXIT
|
||||
|
||||
if ! BAO_TOKEN="$(bao login -method=cert -token-only 2>"$err")"; then
|
||||
echo "the swarm secret store at $BAO_ADDR did not accept this agent's certificate login:" >&2
|
||||
if [ -s "$err" ]; then cat "$err" >&2; fi
|
||||
exit 1
|
||||
fi
|
||||
export BAO_TOKEN
|
||||
|
||||
# An empty directory is a 404, which `bao` answers with `{}` on stdout
|
||||
# and nothing on stderr; a denial or an unreachable store prints
|
||||
# nothing on stdout.
|
||||
if ! bao kv list -format=json ${lib.escapeShellArg accountsDir} >"$list" 2>"$err"; then
|
||||
if [ ! -s "$err" ] && jq -e '. == {}' "$list" >/dev/null 2>&1; then
|
||||
echo "no external forge accounts are linked to this agent (nothing under ${accountsDir})."
|
||||
exit 0
|
||||
fi
|
||||
echo "could not list ${accountsDir}:" >&2
|
||||
if [ -s "$err" ]; then cat "$err" >&2; fi
|
||||
exit 1
|
||||
fi
|
||||
if ! jq -e 'arrays' "$list" >/dev/null; then
|
||||
echo "listing ${accountsDir} returned no array of names." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Moves $1 over $2 and succeeds when the bytes differ; drops $1 otherwise.
|
||||
replace() {
|
||||
if cmp -s "$1" "$2"; then
|
||||
rm -f "$1"
|
||||
return 1
|
||||
fi
|
||||
mv -f "$1" "$2"
|
||||
}
|
||||
|
||||
# One account that cannot be read is logged and skipped. It does not
|
||||
# stop the others, and failing the unit would only restart it into the
|
||||
# same answer.
|
||||
while IFS= read -r label; do
|
||||
# The label becomes a file name, and `hive-forge -f` names only these.
|
||||
# A key ending in `/` is a directory below this one, not an account.
|
||||
if [[ ! "$label" =~ ^[a-z0-9-]+$ ]]; then
|
||||
echo "skipping listed key $(printf '%q' "$label"): not a label hive-forge -f can name." >&2
|
||||
continue
|
||||
fi
|
||||
path="${accountsDir}/$label"
|
||||
if ! bao kv get -format=json "$path" >"$raw" 2>"$err"; then
|
||||
echo "could not read $path; forge-$label files left as they are:" >&2
|
||||
if [ -s "$err" ]; then cat "$err" >&2; fi
|
||||
continue
|
||||
fi
|
||||
|
||||
# ⚠️ The token goes from the store's answer straight into a file;
|
||||
# it is never in a variable or an argument.
|
||||
token=${lib.escapeShellArg stateDir}/forge-$label-token
|
||||
sidecar=${lib.escapeShellArg stateDir}/forge-$label.json
|
||||
staged_token=${lib.escapeShellArg stateDir}/.forge-$label-token.new
|
||||
staged_sidecar=${lib.escapeShellArg stateDir}/.forge-$label.json.new
|
||||
rm -f "$staged_token" "$staged_sidecar"
|
||||
if ! jq -er '.data.data.value | strings' "$raw" >"$staged_token" \
|
||||
|| ! jq -cje '{base_url: (.data.data.url | strings)}' "$raw" >"$staged_sidecar"; then
|
||||
echo "$path holds no string value and url; forge-$label files left as they are." >&2
|
||||
rm -f "$staged_token" "$staged_sidecar"
|
||||
continue
|
||||
fi
|
||||
|
||||
changed=
|
||||
replace "$staged_token" "$token" && changed=1
|
||||
replace "$staged_sidecar" "$sidecar" && changed=1
|
||||
if [ -n "$changed" ]; then
|
||||
echo "fetched external forge account $label from $path."
|
||||
fi
|
||||
done < <(jq -r '.[]' "$list")
|
||||
'';
|
||||
};
|
||||
|
||||
# The same cadence as hive-matrix-daemon's re-listing of its own accounts.
|
||||
systemd.timers.${unitName} = {
|
||||
description = "re-fetch this agent's external forge accounts from the secret store";
|
||||
wantedBy = [ "timers.target" ];
|
||||
timerConfig = {
|
||||
OnUnitInactiveSec = "2min";
|
||||
RandomizedDelaySec = "20s";
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
|
|
@ -112,15 +112,6 @@ in
|
|||
# `/var/lib/nixos-containers/hive-forge/var/lib/forgejo/` survives
|
||||
# restart. See `docs/networking/gateway.md::hive-forge container shape`.
|
||||
|
||||
# External Forgejo/Gitea/Codeberg-compatible forges (beyond the mandatory
|
||||
# internal one) are entirely dashboard-provisioned — no nix config here.
|
||||
# An operator manually creates a token on the external forge (however
|
||||
# that forge lets them) and pastes name + base URL + token into the
|
||||
# dashboard's FORGES tab; hive-c0re just persists it to
|
||||
# `<state>/forge-<label>-token` + a `<state>/forge-<label>.json` sidecar
|
||||
# (base URL), the same shape as the GitHub PAT / matrix extra-account
|
||||
# flows. See `hive-c0re/src/dashboard/extra_forges.rs`.
|
||||
|
||||
imports = [ ./service.nix ];
|
||||
|
||||
# What ./service.nix declares is what the forge IS from any hive's point of
|
||||
|
|
|
|||
|
|
@ -42,6 +42,7 @@ let
|
|||
};
|
||||
|
||||
fetchUnit = machine: machine.systemd.services.hive-agent-forge-token;
|
||||
accountsUnit = machine: machine.systemd.services.hive-agent-forge-accounts;
|
||||
tokenFile = machine: machine.services.hyperhive.agent.forge.tokenFile;
|
||||
in
|
||||
let
|
||||
|
|
@ -164,6 +165,60 @@ let
|
|||
&& !(agentForgeNoBao.systemd.services ? tea-login)
|
||||
&& !(builtins.elem pkgs.tea agentForgeBao.environment.systemPackages);
|
||||
}
|
||||
{
|
||||
name = "an agent with a store address fetches its external forge accounts, and one without does not";
|
||||
ok =
|
||||
agentForgeBao.systemd.services ? hive-agent-forge-accounts
|
||||
&& agentForgeBao.systemd.timers ? hive-agent-forge-accounts
|
||||
&& !(agentForgeNoBao.systemd.services ? hive-agent-forge-accounts)
|
||||
&& !(agentForgeNoBao.systemd.timers ? hive-agent-forge-accounts);
|
||||
}
|
||||
{
|
||||
# The nix half of `swarm_secret_client::forge::{accounts_dir,account_path}`,
|
||||
# and the two file names `hive-forge -f` reads.
|
||||
name = "the account fetch lists the agent's own accounts and reads each into hive-forge's files";
|
||||
ok =
|
||||
let
|
||||
name = agentForgeBao.services.hyperhive.agent.user.name;
|
||||
s = (accountsUnit agentForgeBao).script;
|
||||
in
|
||||
lib.hasInfix "bao kv list -format=json secret/swarm/agents/${name}/forge >" s
|
||||
&& !(lib.hasInfix "/index/" s)
|
||||
&& lib.hasInfix "path=\"secret/swarm/agents/${name}/forge/$label\"" s
|
||||
&& lib.hasInfix "/agents/${name}/state" s
|
||||
&& lib.hasInfix "/forge-$label-token" s
|
||||
&& lib.hasInfix "/forge-$label.json" s
|
||||
&& lib.hasInfix "{base_url: (.data.data.url | strings)}" s;
|
||||
}
|
||||
{
|
||||
# The agent user owns its state dir (./user.nix), and the files keep
|
||||
# the `0600` they have always had.
|
||||
name = "the account fetch runs as the agent, with its own store identity";
|
||||
ok =
|
||||
let
|
||||
u = accountsUnit agentForgeBao;
|
||||
name = agentForgeBao.services.hyperhive.agent.user.name;
|
||||
in
|
||||
u.serviceConfig.User == name
|
||||
&& u.serviceConfig.UMask == "0077"
|
||||
&& builtins.elem "hive-agent-bao-cert" u.serviceConfig.LoadCredential
|
||||
&& u.environment.BAO_CLIENT_CERT == "%d/hive-agent-bao-cert";
|
||||
}
|
||||
{
|
||||
# Files a hive wrote keep working until the operator re-links them.
|
||||
name = "the account fetch never deletes a state-dir file it did not stage";
|
||||
ok =
|
||||
let
|
||||
s = (accountsUnit agentForgeBao).script;
|
||||
in
|
||||
!(lib.hasInfix "rm -f \"$token\"" s)
|
||||
&& !(lib.hasInfix "rm -f \"$sidecar\"" s)
|
||||
&& !(lib.hasInfix "forge-*" s);
|
||||
}
|
||||
{
|
||||
name = "the account fetch re-runs every two minutes";
|
||||
ok = agentForgeBao.systemd.timers.hive-agent-forge-accounts.timerConfig.OnUnitInactiveSec == "2min";
|
||||
}
|
||||
];
|
||||
in
|
||||
runGroup "agent-forge-bao" cases
|
||||
|
|
|
|||
Loading…
Reference in a new issue