swarm UI: show the accounts linked to each agent
GET /api/hives/{hive}/agents/{agent}/linked-accounts returns one row per
account linked to the agent, as kind, name and host: each matrix account
under swarm/agents/<agent>/matrix (with its homeserver, and the agent's own
`main` marked reserved), each forge label under swarm/agents/<agent>/forge
(with its url), and github when swarm/agents/<agent>/github-token exists
(host github.com, which is not stored). No credential field is in the
response type.
Listing those two directories needs a new controller grant: `list` on
secret/metadata/swarm/agents/+/matrix and .../+/forge only, pinned in
bao-grants.nix as the only metadata stanzas under agents/ beside the queue
revocation. Checked against a dev OpenBao 2.6.3: the grant lists those two
directories and is refused on agents/, agents/<agent>/, and a leaf.
The swarm UI agent detail panel shows all rows under "accounts"; the table
view's matrix column shows the matrix rows. The link badges stay.
Refs #4855
This commit is contained in:
parent
6fd91b0e69
commit
3380c1915f
13 changed files with 577 additions and 30 deletions
|
|
@ -23,7 +23,23 @@ An agent created here or with `swarmctl agent create` starts `paused`; set it
|
|||
|
||||
Each agent on `/agents` opens three dialogs that write a credential for it
|
||||
into the swarm secret store through swarm-controller. All three are blind
|
||||
set/update actions: no route lists linked accounts or hands a token back.
|
||||
set/update actions: no route hands a token back.
|
||||
|
||||
The agent's detail panel lists its linked accounts under **accounts**, one row
|
||||
per account: kind, name and host. The table view's matrix column lists the
|
||||
matrix rows. Both come from
|
||||
`GET /api/hives/{hive}/agents/{agent}/linked-accounts`, which returns names
|
||||
and hosts and never a credential.
|
||||
|
||||
| kind | one row per | name | host |
|
||||
| ------- | ------------------------------------------- | ----------- | ------------------------ |
|
||||
| matrix | `swarm/agents/<agent>/matrix/<account>` | the account | its `homeserver`, if set |
|
||||
| forgejo | `swarm/agents/<agent>/forge/<label>` | the label | its `url` |
|
||||
| github | `swarm/agents/<agent>/github-token`, if any | `github` | `github.com` |
|
||||
|
||||
The matrix `main` row is the agent's own account, which the swarm mints;
|
||||
it carries an **own account** badge. The lists refresh when a link dialog
|
||||
closes.
|
||||
|
||||
- **link a matrix account** — `PUT /api/hives/{hive}/agents/{agent}/matrix-accounts/{account}`,
|
||||
either a pasted bearer token or a user id + password that
|
||||
|
|
|
|||
Loading…
Reference in a new issue