From 7488c337ccdf302471bc2e0e9eb58418c462f593 Mon Sep 17 00:00:00 2001 From: atlas Date: Fri, 2 Oct 2026 17:56:06 +0200 Subject: [PATCH] docs(swarm): drop stale github-token exception in credentials.md The sentence claiming a per-agent github token sits outside this page and never passes through the store contradicted the swarm/agents//github-token row already in the table: the token is minted by swarm-controller and read by hive-agent-github-token through bao like every other row. Refs #4347 --- docs/swarm/credentials.md | 4 ---- 1 file changed, 4 deletions(-) diff --git a/docs/swarm/credentials.md b/docs/swarm/credentials.md index 5f5650a8..89e63765 100644 --- a/docs/swarm/credentials.md +++ b/docs/swarm/credentials.md @@ -42,10 +42,6 @@ to the store under its own name, pulling what it needs when it needs it. No process reads a secret on another principal's behalf: the principal that needs a value is the principal that authenticates for it. -One per-agent credential file — the github token — sits outside this page: -it's operator-supplied and never passes through the store, so the table -below doesn't govern it. - **Per secret, the target specifies minter, reader, and renewal strategy.** Those three are the contract, and the reader is a process pulling a store path at runtime — not a path on disk, and not a unit whose job is to turn a