Make agent creation swarm-only and refuse a name placed on another hive
swarm-controller's POST /api/agents now refuses (409) a name the swarm
has already placed on a different hive: a non-Destroyed declaration in
that hive's wanted state, or a SetAgentWanted node still queued for it.
The same name on the same hive is that agent being re-created and goes
through. A wanted state that cannot be read refuses (503/500) instead of
reading as "placed nowhere". Creations are serialised from that read to
the graph insert so two concurrent creations of one name cannot both
pass.
Hive-level creation is removed: hivectl `agent create` / `request-create`,
HostRequest::Spawn / RequestSpawn, the dashboard POST /api/request-spawn
route, and ApprovalKind::Spawn with its approve/resolve arms and the
approval-carrying `templates::spawn`. The swarm path (deploy request or
wanted-state sweep -> queue_first_deploy -> templates::first_deploy) used
none of them. Old `spawn` approval rows are skipped by collect_lenient,
as `init_config` rows were in a3b672d1.
policy.rs's comment on agent_object_name stated swarm-wide name
uniqueness as a fact; it now says where it is enforced and what that
check cannot see.
Refs #4396
This commit is contained in:
parent
1d8ec00ddc
commit
5785c0024c
35 changed files with 376 additions and 434 deletions
|
|
@ -117,20 +117,6 @@ pub enum ReconcileDirection {
|
|||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
#[serde(tag = "cmd", rename_all = "snake_case")]
|
||||
pub enum HostRequest {
|
||||
/// Create and start a brand-new sub-agent container directly (full
|
||||
/// first-time provisioning: proposed/applied repos, state subvolume,
|
||||
/// meta-flake sync, `nixos-container create`), bypassing the approval
|
||||
/// queue. Privileged-context only. Exposed on the CLI as `hivectl
|
||||
/// agent <name> create`. See `docs/agent-lifecycle/approvals.md::Approval kinds
|
||||
/// (wire shapes)`. Wire name kept as `Spawn` (unrenamed underneath
|
||||
/// the CLI-verb rename — `hivectl agent <name> start` reuses the
|
||||
/// existing scope-based [`HostRequest::Start`] below instead of a
|
||||
/// new per-agent variant, see its doc comment).
|
||||
Spawn { name: Ident },
|
||||
/// Submit a first-creation request for the operator to approve. See
|
||||
/// `docs/agent-lifecycle/approvals.md::Approval kinds (wire shapes)` (`Spawn`).
|
||||
/// Exposed on the CLI as `hivectl agent <name> request-create`.
|
||||
RequestSpawn { name: Ident },
|
||||
/// Hard stop a managed container. Exposed on the CLI as `hivectl
|
||||
/// agent <name> kill` — kept distinct from the new graceful-only
|
||||
/// `hivectl agent <name> stop` (which reuses the scope-based
|
||||
|
|
|
|||
Loading…
Reference in a new issue