swarm-controller: backfill a missing queue-secret mint time instead of re-minting it
A stored queue secret with no `minted_at` counted as due, and no secret minted before the renewal pass has one, so the first pass after deploy would re-mint every agent's secret. Every reconnect before that agent's next restart would then be refused. Such a secret is now stamped instead: `minted_at = now` is written beside the unchanged `value`, and its 45-day clock starts there. Only a secret whose recorded mint time is at least 45 days old gets a new value. The decision is `secret_step` (Keep / Backfill / Remint), and the pass reports an unstamped secret as `Observed::Unstamped`. Backfill and re-mint log different lines.
This commit is contained in:
parent
2115ec2bb3
commit
7bc4b25f16
3 changed files with 150 additions and 84 deletions
|
|
@ -103,7 +103,8 @@ pub struct AgentCredential {
|
|||
pub agent: String,
|
||||
|
||||
/// When `value` was minted, in unix seconds. `swarm-controller` re-mints
|
||||
/// the secret once this is old enough, and treats `None` as due.
|
||||
/// the secret once this is old enough, and fills in `None` with the time it
|
||||
/// first sees it, leaving `value` alone.
|
||||
///
|
||||
/// `Option` because objects written before this field existed lack it and
|
||||
/// must still decode; skipped when `None` so such an object re-serialises
|
||||
|
|
|
|||
Loading…
Reference in a new issue