forge: external forge accounts live in swarm bao; the agent fetches them itself
An operator now links an agent's external forge account (label, base URL, token) in the swarm UI. swarm-controller stores it at swarm/agents/<agent>/forge/<label>. There is no index: the store's listing of the agent's forge/ directory is the set of accounts. In the agent, hive-agent-forge-accounts (oneshot + 2-minute timer, as the agent user, under its own store certificate) lists swarm/agents/<agent>/forge/ with the `list` #4866 grants an agent on its own metadata subtree, reads each account, and writes <state>/forge-<label>-token and forge-<label>.json in the names and shape hive-forge -f already reads. An empty listing (a 404, which `bao kv list -format=json` answers with `{}` and an empty stderr) is zero accounts; a denial or an unreachable store fails the unit. It never deletes: files for labels not listed, including ones the hive wrote, stay as they are. Removed: the dashboard FORGES tab (credentials.js/html section and its CSS), hive-c0re's extra_forges.rs and its routes, priv_client's extra-forge calls, and hive-priv's WriteAgentExtraForgeAccount / DeleteAgentExtraForgeAccount with their helpers. The GITHUB tab and WriteAgentGithubToken stay. Also: persistence.md's matrix avatar note names the exit-75 restart on a changed account listing, not the dashboard, as what brings a linked account up. Refs #4348
This commit is contained in:
parent
97fb76ce99
commit
2c7e586f47
27 changed files with 815 additions and 748 deletions
|
|
@ -112,15 +112,6 @@ in
|
|||
# `/var/lib/nixos-containers/hive-forge/var/lib/forgejo/` survives
|
||||
# restart. See `docs/networking/gateway.md::hive-forge container shape`.
|
||||
|
||||
# External Forgejo/Gitea/Codeberg-compatible forges (beyond the mandatory
|
||||
# internal one) are entirely dashboard-provisioned — no nix config here.
|
||||
# An operator manually creates a token on the external forge (however
|
||||
# that forge lets them) and pastes name + base URL + token into the
|
||||
# dashboard's FORGES tab; hive-c0re just persists it to
|
||||
# `<state>/forge-<label>-token` + a `<state>/forge-<label>.json` sidecar
|
||||
# (base URL), the same shape as the GitHub PAT / matrix extra-account
|
||||
# flows. See `hive-c0re/src/dashboard/extra_forges.rs`.
|
||||
|
||||
imports = [ ./service.nix ];
|
||||
|
||||
# What ./service.nix declares is what the forge IS from any hive's point of
|
||||
|
|
|
|||
Loading…
Reference in a new issue