docs/setup: ruth needs a store identity and a rebuild, not a hand-made forge user
The rewritten ruth step skipped her store identity, without which neither the backfill nor her container's fetch can reach her token. With the backfill now creating a missing forge user, two commands cover her: swarmctl agent mint-identity ruth --hive <hive>, then hivectl agent ruth rebuild so hive-c0re hands the identity to her container. Refs #3782
This commit is contained in:
parent
22f0acfd6d
commit
3ee5a960b4
3 changed files with 26 additions and 12 deletions
|
|
@ -52,7 +52,8 @@ Each agent gets its own Forgejo user and access token. swarm-controller
|
|||
creates the user when it creates the agent, and mints one token named
|
||||
`swarm-agent` with the admin API into the swarm secret store at
|
||||
`swarm/agents/<agent>/forge-token`. A pass at start and every five minutes
|
||||
re-mints any agent's token that's missing or no longer matches the forge;
|
||||
covers every agent with a store identity: it creates a missing forge user and
|
||||
re-mints any token that's missing or no longer matches the forge;
|
||||
a rotation deletes the old `swarm-agent` token first, so each agent holds at
|
||||
most one. The agent fetches the token under its own store certificate into
|
||||
`/run/hive-agent-forge-token/token` (`nix/agent-modules/forge-token.nix`),
|
||||
|
|
|
|||
Loading…
Reference in a new issue