diff --git a/docs/swarm/credentials.md b/docs/swarm/credentials.md index 5f5650a8..89e63765 100644 --- a/docs/swarm/credentials.md +++ b/docs/swarm/credentials.md @@ -42,10 +42,6 @@ to the store under its own name, pulling what it needs when it needs it. No process reads a secret on another principal's behalf: the principal that needs a value is the principal that authenticates for it. -One per-agent credential file — the github token — sits outside this page: -it's operator-supplied and never passes through the store, so the table -below doesn't govern it. - **Per secret, the target specifies minter, reader, and renewal strategy.** Those three are the contract, and the reader is a process pulling a store path at runtime — not a path on disk, and not a unit whose job is to turn a