Watch
0
0
Fork
You've already forked hyperhive
0

swarm-controller: mint each agent's forge token and store it in bao

A MintAgentForgeToken node mints a fixed-name swarm-agent token with the
admin API, keeps it when the stored value's last eight and the normalised
scopes match the forge's list, and otherwise deletes and re-creates it.
The token is stored at swarm/agents/<agent>/forge-token. Agent creation
inserts the node, and a pass at start and every five minutes inserts it
for every agent holding a store identity whose token is missing or stale.

Refs #3782
This commit is contained in:
atlas 2026-09-24 16:29:04 +02:00 • committed by mara
commit 52c8c0b0de
7 changed files with 977 additions and 4 deletions

View file

@ -33,6 +33,8 @@ use utoipa::ToSchema;
use crate::webhook::DeliveryKind;
pub mod agent_token;
/// An agent's open config-PR, as [`Client::list_open_config_prs`] reports it
/// and `GET /api/agents/{name}/config-pr` serves it.
#[derive(Clone, Debug, PartialEq, Serialize, Deserialize, ToSchema)]
@ -135,6 +137,10 @@ const TOKEN_FILE_ENV: &str = "SWARM_CONTROLLER_FORGE_TOKEN_FILE";
/// Typed forgejo client, built once at startup from env.
pub struct Client {
api: Forgejo,
/// The forge's base URL, kept so a client authenticated as someone
/// else can be built against the same forge (see
/// [`agent_token`]'s read-back).
url: url::Url,
}
impl Client {
@ -168,8 +174,12 @@ impl Client {
}
let parsed_url =
url::Url::parse(&url).with_context(|| format!("parse {URL_ENV} ({url}) as a URL"))?;
let api = Forgejo::new(Auth::Token(token), parsed_url).context("build forgejo client")?;
Ok(Some(Self { api }))
let api =
Forgejo::new(Auth::Token(token), parsed_url.clone()).context("build forgejo client")?;
Ok(Some(Self {
api,
url: parsed_url,
}))
}
/// Creation options for an empty repo defaulting to `main`.