Watch
0
0
Fork
You've already forked hyperhive
0

swarm-controller: mint each agent's forge token and store it in bao

A MintAgentForgeToken node mints a fixed-name swarm-agent token with the
admin API, keeps it when the stored value's last eight and the normalised
scopes match the forge's list, and otherwise deletes and re-creates it.
The token is stored at swarm/agents/<agent>/forge-token. Agent creation
inserts the node, and a pass at start and every five minutes inserts it
for every agent holding a store identity whose token is missing or stale.

Refs #3782
This commit is contained in:
atlas 2026-09-24 16:29:04 +02:00 • committed by mara
commit 52c8c0b0de
7 changed files with 977 additions and 4 deletions

View file

@ -5,7 +5,7 @@
//! the rules every path obeys ([`path`]), the translation from this
//! deployment's environment into a logged-in client ([`client`]), and, per kind
//! of secret, the path it lives at together with the fields it holds
//! ([`matrix`], [`queue`], [`mtls`]). Each of those is a thing the controller
//! ([`matrix`], [`queue`], [`mtls`], [`forge`]). Each of those is a thing the controller
//! and a hive must say identically, so it is said once here.
//!
//! [`policy`] is the same kind of agreement seen from the other side: which of
@ -23,6 +23,7 @@
//! value inside it, and its doc explains why that is not circular.
pub mod client;
pub mod forge;
pub mod matrix;
pub mod mtls;
pub mod path;