forge: external forge accounts live in swarm bao; the agent fetches them itself
An operator now links an agent's external forge account (label, base URL, token) in the swarm UI. swarm-controller stores it at swarm/agents/<agent>/forge/<label>. There is no index: the store's listing of the agent's forge/ directory is the set of accounts. In the agent, hive-agent-forge-accounts (oneshot + 2-minute timer, as the agent user, under its own store certificate) lists swarm/agents/<agent>/forge/ with the `list` #4866 grants an agent on its own metadata subtree, reads each account, and writes <state>/forge-<label>-token and forge-<label>.json in the names and shape hive-forge -f already reads. An empty listing (a 404, which `bao kv list -format=json` answers with `{}` and an empty stderr) is zero accounts; a denial or an unreachable store fails the unit. It never deletes: files for labels not listed, including ones the hive wrote, stay as they are. Removed: the dashboard FORGES tab (credentials.js/html section and its CSS), hive-c0re's extra_forges.rs and its routes, priv_client's extra-forge calls, and hive-priv's WriteAgentExtraForgeAccount / DeleteAgentExtraForgeAccount with their helpers. The GITHUB tab and WriteAgentGithubToken stay. Also: persistence.md's matrix avatar note names the exit-75 restart on a changed account listing, not the dashboard, as what brings a linked account up. Refs #4348
This commit is contained in:
parent
97fb76ce99
commit
2c7e586f47
27 changed files with 815 additions and 748 deletions
|
|
@ -46,6 +46,7 @@ in
|
|||
./dashboard-links.nix
|
||||
./docs.nix
|
||||
./forge.nix
|
||||
./forge-accounts.nix
|
||||
./forge-token.nix
|
||||
./frontend.nix
|
||||
./github.nix
|
||||
|
|
|
|||
191
nix/agent-modules/forge-accounts.nix
Normal file
191
nix/agent-modules/forge-accounts.nix
Normal file
|
|
@ -0,0 +1,191 @@
|
|||
# This agent's accounts on external forges, fetched from the swarm secret store
|
||||
# by the agent itself, into the files `hive-forge -f <label>` reads.
|
||||
#
|
||||
# An operator links an account in the swarm UI; `swarm-controller` stores it at
|
||||
# `swarm/agents/<agent>/forge/<label>` (`swarm_secret_client::forge`). The
|
||||
# agent's grant lists and reads its own subtree, so this unit lists
|
||||
# `swarm/agents/<agent>/forge/`, reads each account, and writes
|
||||
# `<state>/forge-<label>-token` and `<state>/forge-<label>.json`
|
||||
# (`{"base_url":…}`), the two files `hive-forge`'s `resolve_credentials` reads.
|
||||
#
|
||||
# It never deletes. A `forge-<label>` pair for a label not listed is left
|
||||
# as it is, whoever wrote it, and so is the pair of a label whose read fails.
|
||||
# A file is replaced by rename, and only when its bytes changed.
|
||||
{
|
||||
pkgs,
|
||||
lib,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
let
|
||||
cfg = config.services.hyperhive.agent.bao;
|
||||
|
||||
agentName = config.services.hyperhive.agent.user.name;
|
||||
stateDir = "/agents/${agentName}/state";
|
||||
|
||||
# The same three ids ./bao.nix and ./forge-token.nix load.
|
||||
certCredential = "hive-agent-bao-cert";
|
||||
keyCredential = "hive-agent-bao-key";
|
||||
serverCaCredential = "hive-agent-bao-server-ca";
|
||||
|
||||
unitName = "hive-agent-forge-accounts";
|
||||
|
||||
# The nix half of `swarm_secret_client::forge::accounts_dir` plus
|
||||
# `path::MOUNT`.
|
||||
accountsDir = "secret/swarm/agents/${agentName}/forge";
|
||||
|
||||
runtimeDir = unitName;
|
||||
# The store's whole answer for one account, token included: kept in the
|
||||
# unit's own `0700` directory, never in the state dir.
|
||||
rawFile = "/run/${runtimeDir}/account.json";
|
||||
listFile = "/run/${runtimeDir}/list.json";
|
||||
errFile = "/run/${runtimeDir}/bao.err";
|
||||
|
||||
configured = cfg.addr != null;
|
||||
|
||||
storeRetry = import ../host-modules/lib/store-retry.nix { };
|
||||
in
|
||||
{
|
||||
config = lib.mkIf configured {
|
||||
systemd.services.${unitName} = {
|
||||
description = "fetch this agent's external forge accounts from the secret store";
|
||||
after = [
|
||||
"network.target"
|
||||
"hive-agent-bao-identity.service"
|
||||
];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
path = [
|
||||
pkgs.openbao
|
||||
pkgs.coreutils
|
||||
pkgs.diffutils
|
||||
pkgs.jq
|
||||
];
|
||||
# ../host-modules/lib/store-retry.nix.
|
||||
inherit (storeRetry) startLimitBurst startLimitIntervalSec;
|
||||
serviceConfig = storeRetry.serviceConfig // {
|
||||
Type = "oneshot";
|
||||
# Not `RemainAfterExit`, so the timer below can start it again.
|
||||
RemainAfterExit = false;
|
||||
TimeoutStartSec = 60;
|
||||
User = agentName;
|
||||
Group = agentName;
|
||||
RuntimeDirectory = runtimeDir;
|
||||
RuntimeDirectoryMode = "0700";
|
||||
# `0600`, the mode the files in the state dir have always had.
|
||||
UMask = "0077";
|
||||
LoadCredential = [
|
||||
certCredential
|
||||
keyCredential
|
||||
serverCaCredential
|
||||
];
|
||||
};
|
||||
environment = {
|
||||
BAO_ADDR = cfg.addr;
|
||||
BAO_CLIENT_CERT = "%d/${certCredential}";
|
||||
BAO_CLIENT_KEY = "%d/${keyCredential}";
|
||||
};
|
||||
script = ''
|
||||
set -euo pipefail
|
||||
|
||||
# No identity delivered: ./bao.nix's check reports that.
|
||||
for id in ${lib.escapeShellArg certCredential} ${lib.escapeShellArg keyCredential}; do
|
||||
if [ ! -s "$CREDENTIALS_DIRECTORY/$id" ]; then
|
||||
echo "this agent has no store identity, so it cannot fetch its external forge accounts." >&2
|
||||
exit 0
|
||||
fi
|
||||
done
|
||||
|
||||
if [ -s "$CREDENTIALS_DIRECTORY/${serverCaCredential}" ]; then
|
||||
export BAO_CACERT="$CREDENTIALS_DIRECTORY/${serverCaCredential}"
|
||||
fi
|
||||
|
||||
err=${lib.escapeShellArg errFile}
|
||||
raw=${lib.escapeShellArg rawFile}
|
||||
list=${lib.escapeShellArg listFile}
|
||||
trap 'rm -f "$err" "$raw" "$list"' EXIT
|
||||
|
||||
if ! BAO_TOKEN="$(bao login -method=cert -token-only 2>"$err")"; then
|
||||
echo "the swarm secret store at $BAO_ADDR did not accept this agent's certificate login:" >&2
|
||||
if [ -s "$err" ]; then cat "$err" >&2; fi
|
||||
exit 1
|
||||
fi
|
||||
export BAO_TOKEN
|
||||
|
||||
# An empty directory is a 404, which `bao` answers with `{}` on stdout
|
||||
# and nothing on stderr; a denial or an unreachable store prints
|
||||
# nothing on stdout.
|
||||
if ! bao kv list -format=json ${lib.escapeShellArg accountsDir} >"$list" 2>"$err"; then
|
||||
if [ ! -s "$err" ] && jq -e '. == {}' "$list" >/dev/null 2>&1; then
|
||||
echo "no external forge accounts are linked to this agent (nothing under ${accountsDir})."
|
||||
exit 0
|
||||
fi
|
||||
echo "could not list ${accountsDir}:" >&2
|
||||
if [ -s "$err" ]; then cat "$err" >&2; fi
|
||||
exit 1
|
||||
fi
|
||||
if ! jq -e 'arrays' "$list" >/dev/null; then
|
||||
echo "listing ${accountsDir} returned no array of names." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Moves $1 over $2 and succeeds when the bytes differ; drops $1 otherwise.
|
||||
replace() {
|
||||
if cmp -s "$1" "$2"; then
|
||||
rm -f "$1"
|
||||
return 1
|
||||
fi
|
||||
mv -f "$1" "$2"
|
||||
}
|
||||
|
||||
# One account that cannot be read is logged and skipped. It does not
|
||||
# stop the others, and failing the unit would only restart it into the
|
||||
# same answer.
|
||||
while IFS= read -r label; do
|
||||
# The label becomes a file name, and `hive-forge -f` names only these.
|
||||
# A key ending in `/` is a directory below this one, not an account.
|
||||
if [[ ! "$label" =~ ^[a-z0-9-]+$ ]]; then
|
||||
echo "skipping listed key $(printf '%q' "$label"): not a label hive-forge -f can name." >&2
|
||||
continue
|
||||
fi
|
||||
path="${accountsDir}/$label"
|
||||
if ! bao kv get -format=json "$path" >"$raw" 2>"$err"; then
|
||||
echo "could not read $path; forge-$label files left as they are:" >&2
|
||||
if [ -s "$err" ]; then cat "$err" >&2; fi
|
||||
continue
|
||||
fi
|
||||
|
||||
# ⚠️ The token goes from the store's answer straight into a file;
|
||||
# it is never in a variable or an argument.
|
||||
token=${lib.escapeShellArg stateDir}/forge-$label-token
|
||||
sidecar=${lib.escapeShellArg stateDir}/forge-$label.json
|
||||
staged_token=${lib.escapeShellArg stateDir}/.forge-$label-token.new
|
||||
staged_sidecar=${lib.escapeShellArg stateDir}/.forge-$label.json.new
|
||||
rm -f "$staged_token" "$staged_sidecar"
|
||||
if ! jq -er '.data.data.value | strings' "$raw" >"$staged_token" \
|
||||
|| ! jq -cje '{base_url: (.data.data.url | strings)}' "$raw" >"$staged_sidecar"; then
|
||||
echo "$path holds no string value and url; forge-$label files left as they are." >&2
|
||||
rm -f "$staged_token" "$staged_sidecar"
|
||||
continue
|
||||
fi
|
||||
|
||||
changed=
|
||||
replace "$staged_token" "$token" && changed=1
|
||||
replace "$staged_sidecar" "$sidecar" && changed=1
|
||||
if [ -n "$changed" ]; then
|
||||
echo "fetched external forge account $label from $path."
|
||||
fi
|
||||
done < <(jq -r '.[]' "$list")
|
||||
'';
|
||||
};
|
||||
|
||||
# The same cadence as hive-matrix-daemon's re-listing of its own accounts.
|
||||
systemd.timers.${unitName} = {
|
||||
description = "re-fetch this agent's external forge accounts from the secret store";
|
||||
wantedBy = [ "timers.target" ];
|
||||
timerConfig = {
|
||||
OnUnitInactiveSec = "2min";
|
||||
RandomizedDelaySec = "20s";
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
Loading…
Reference in a new issue