swarm-controller: create every agent's subagent stream
swarm-controller now creates `term-sub-<agent>` for every agent a hive is declared to run, at start and every minute after, with the config `swarm_queue_client::subagent_term::open_or_create` spells (subjects `$SWARM.term.<agent>.sub.>`, max_age 24h). An existing stream is opened as it is, as the controller does for its other streams and buckets, under the `$JS.API.STREAM.CREATE.*` grant it already holds. The agent no longer creates the stream: its token is granted publish on `$SWARM.term.<agent>.sub.>` and no `$JS.API.STREAM.CREATE|INFO` subject, and the subagent daemon only publishes. A `CREATE` carries the stream's config in its payload, which no subject grant narrows, so the agent could otherwise pick the stream's subjects and limits.
This commit is contained in:
parent
d6f94e5247
commit
318f67cda9
13 changed files with 135 additions and 102 deletions
|
|
@ -844,16 +844,12 @@ in
|
|||
# on a hive presents that one, so it cannot be scoped to one
|
||||
# agent's key.
|
||||
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$KV.agent-icons.{agent}"}"
|
||||
# Its subagents' terminal rows, and the one stream that keeps
|
||||
# them (`swarm_queue_client::subagent_term`). The agent's
|
||||
# subagent daemon creates the stream on first use, so it gets
|
||||
# `CREATE` and `INFO` on that stream name alone: no `UPDATE`,
|
||||
# no `DELETE`, no consumer, no other stream. A `CREATE`'s
|
||||
# config travels in its payload, which no subject grant can
|
||||
# narrow.
|
||||
# Its subagents' terminal rows
|
||||
# (`swarm_queue_client::subagent_term`), publish only and no
|
||||
# `$JS.API.*` subject: swarm-controller creates the
|
||||
# `term-sub-{agent}` stream that keeps them, so its subjects
|
||||
# and limits are never the agent's to choose.
|
||||
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$SWARM.term.{agent}.sub.>"}"
|
||||
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$JS.API.STREAM.CREATE.term-sub-{agent}"}"
|
||||
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$JS.API.STREAM.INFO.term-sub-{agent}"}"
|
||||
"--store-cert-role ${lib.escapeShellArg authCertRole}"
|
||||
];
|
||||
# Every credential arrives by `LoadCredential` and is named
|
||||
|
|
|
|||
|
|
@ -165,7 +165,7 @@ let
|
|||
# The whole per-agent grant, compared as a list rather than by infix: a
|
||||
# wider subject added beside these (`$$JS.API.>`, another stream's name)
|
||||
# would pass every presence check above.
|
||||
name = "a verified agent's grant is exactly its own subjects and its subagent stream";
|
||||
name = "a verified agent's grant is exactly its own subjects, with no JetStream API subject";
|
||||
ok =
|
||||
let
|
||||
args = lib.splitString " " (responderOf natsOldPath).serviceConfig.ExecStart;
|
||||
|
|
@ -183,8 +183,6 @@ let
|
|||
"'$$SWARM.agent-state.{agent}'"
|
||||
"'$$KV.agent-icons.{agent}'"
|
||||
"'$$SWARM.term.{agent}.sub.>'"
|
||||
"'$$JS.API.STREAM.CREATE.term-sub-{agent}'"
|
||||
"'$$JS.API.STREAM.INFO.term-sub-{agent}'"
|
||||
];
|
||||
}
|
||||
{
|
||||
|
|
|
|||
Loading…
Reference in a new issue