docs/setup: ruth needs a store identity and a rebuild, not a hand-made forge user
The rewritten ruth step skipped her store identity, without which neither the backfill nor her container's fetch can reach her token. With the backfill now creating a missing forge user, two commands cover her: swarmctl agent mint-identity ruth --hive <hive>, then hivectl agent ruth rebuild so hive-c0re hands the identity to her container. Refs #3782
This commit is contained in:
parent
22f0acfd6d
commit
3ee5a960b4
3 changed files with 26 additions and 12 deletions
|
|
@ -24,18 +24,30 @@ operator has to place, and where.
|
|||
|
||||
### 1 · Forge
|
||||
|
||||
hive-c0re no longer creates agent forge users or mints agent tokens.
|
||||
swarm-controller does, for every agent that holds a store identity: a pass
|
||||
at start and every five minutes creates the forge user if it's missing,
|
||||
then mints the token into the swarm secret store, where the agent fetches
|
||||
it under that identity. An agent created with `swarmctl agent create` gets
|
||||
its identity then. Ruth doesn't: hive-c0re creates her on its own at
|
||||
startup, so she needs her identity minted by hand, once.
|
||||
|
||||
```bash
|
||||
# hive-c0re no longer creates agent forge users or mints agent tokens:
|
||||
# swarm-controller does, for agents created at swarm level
|
||||
# (`swarmctl agent create`), and stores the token in the swarm secret store,
|
||||
# where the agent fetches it. An agent that only ever existed on this hive —
|
||||
# ruth's bootstrap, or the hive's own spawn-approval flow — gets no forge
|
||||
# user from anything yet. Create that user in the forge's admin UI; once the
|
||||
# agent has a store identity (`swarmctl agent mint-identity`), swarm-controller
|
||||
# mints its token within five minutes, or at once with:
|
||||
swarmctl agent mint-forge-token ruth
|
||||
# On the swarm-controller host: give ruth her store identity. <hive> is the
|
||||
# name of the hive she runs on.
|
||||
swarmctl agent mint-identity ruth --hive <hive>
|
||||
|
||||
# On ruth's hive: re-apply her container config, which is when hive-c0re
|
||||
# hands the new identity to the container.
|
||||
hivectl agent ruth rebuild
|
||||
```
|
||||
|
||||
You don't need to do anything else. The controller's next pass creates
|
||||
ruth's forge user and mints her token, and her container fetches it within
|
||||
about ten minutes. `swarmctl agent mint-forge-token ruth` skips the wait for
|
||||
the pass. A hive without a swarm secret store has no path to a forge token
|
||||
for ruth at all.
|
||||
|
||||
Swarm SSO creates the human operator's own forge account instead of
|
||||
a manual `hivectl` step — see _Swarm SSO_ below (`swarmctl user add`).
|
||||
|
||||
|
|
|
|||
|
|
@ -52,7 +52,8 @@ Each agent gets its own Forgejo user and access token. swarm-controller
|
|||
creates the user when it creates the agent, and mints one token named
|
||||
`swarm-agent` with the admin API into the swarm secret store at
|
||||
`swarm/agents/<agent>/forge-token`. A pass at start and every five minutes
|
||||
re-mints any agent's token that's missing or no longer matches the forge;
|
||||
covers every agent with a store identity: it creates a missing forge user and
|
||||
re-mints any token that's missing or no longer matches the forge;
|
||||
a rotation deletes the old `swarm-agent` token first, so each agent holds at
|
||||
most one. The agent fetches the token under its own store certificate into
|
||||
`/run/hive-agent-forge-token/token` (`nix/agent-modules/forge-token.nix`),
|
||||
|
|
|
|||
|
|
@ -97,8 +97,9 @@ its queue connection. The certificate half isn't: the agent gets a fresh leaf
|
|||
and picks it up on its next boot.
|
||||
|
||||
The forge token needs no such step: `swarm-controller` checks every agent
|
||||
that has a store identity at start and every five minutes, and mints a token
|
||||
for any whose stored one is missing or stale. To check one agent now:
|
||||
that has a store identity at start and every five minutes. For any whose
|
||||
stored token is missing or stale it creates the forge user if there isn't one,
|
||||
then mints the token. To check one agent now:
|
||||
|
||||
```sh
|
||||
swarmctl agent mint-forge-token <agent>
|
||||
|
|
|
|||
Loading…
Reference in a new issue