swarm-controller: mint each agent's forge token and store it in bao
A MintAgentForgeToken node mints a fixed-name swarm-agent token with the admin API, keeps it when the stored value's last eight and the normalised scopes match the forge's list, and otherwise deletes and re-creates it. The token is stored at swarm/agents/<agent>/forge-token. Agent creation inserts the node, and a pass at start and every five minutes inserts it for every agent holding a store identity whose token is missing or stale. Refs #3782
This commit is contained in:
parent
2fda529ca8
commit
52c8c0b0de
7 changed files with 977 additions and 4 deletions
|
|
@ -33,6 +33,8 @@ use utoipa::ToSchema;
|
|||
|
||||
use crate::webhook::DeliveryKind;
|
||||
|
||||
pub mod agent_token;
|
||||
|
||||
/// An agent's open config-PR, as [`Client::list_open_config_prs`] reports it
|
||||
/// and `GET /api/agents/{name}/config-pr` serves it.
|
||||
#[derive(Clone, Debug, PartialEq, Serialize, Deserialize, ToSchema)]
|
||||
|
|
@ -135,6 +137,10 @@ const TOKEN_FILE_ENV: &str = "SWARM_CONTROLLER_FORGE_TOKEN_FILE";
|
|||
/// Typed forgejo client, built once at startup from env.
|
||||
pub struct Client {
|
||||
api: Forgejo,
|
||||
/// The forge's base URL, kept so a client authenticated as someone
|
||||
/// else can be built against the same forge (see
|
||||
/// [`agent_token`]'s read-back).
|
||||
url: url::Url,
|
||||
}
|
||||
|
||||
impl Client {
|
||||
|
|
@ -168,8 +174,12 @@ impl Client {
|
|||
}
|
||||
let parsed_url =
|
||||
url::Url::parse(&url).with_context(|| format!("parse {URL_ENV} ({url}) as a URL"))?;
|
||||
let api = Forgejo::new(Auth::Token(token), parsed_url).context("build forgejo client")?;
|
||||
Ok(Some(Self { api }))
|
||||
let api =
|
||||
Forgejo::new(Auth::Token(token), parsed_url.clone()).context("build forgejo client")?;
|
||||
Ok(Some(Self {
|
||||
api,
|
||||
url: parsed_url,
|
||||
}))
|
||||
}
|
||||
|
||||
/// Creation options for an empty repo defaulting to `main`.
|
||||
|
|
|
|||
Loading…
Reference in a new issue