Watch
0
0
Fork
You've already forked hyperhive
0

swarm-controller: backfill a missing queue-secret mint time instead of re-minting it

A stored queue secret with no `minted_at` counted as due, and no secret
minted before the renewal pass has one, so the first pass after deploy
would re-mint every agent's secret. Every reconnect before that agent's
next restart would then be refused.

Such a secret is now stamped instead: `minted_at = now` is written beside
the unchanged `value`, and its 45-day clock starts there. Only a secret
whose recorded mint time is at least 45 days old gets a new value.

The decision is `secret_step` (Keep / Backfill / Remint), and the pass
reports an unstamped secret as `Observed::Unstamped`. Backfill and
re-mint log different lines.
This commit is contained in:
atlas 2026-09-28 22:24:07 +02:00
commit 7bc4b25f16
3 changed files with 150 additions and 84 deletions

View file

@ -103,7 +103,8 @@ pub struct AgentCredential {
pub agent: String,
/// When `value` was minted, in unix seconds. `swarm-controller` re-mints
/// the secret once this is old enough, and treats `None` as due.
/// the secret once this is old enough, and fills in `None` with the time it
/// first sees it, leaving `value` alone.
///
/// `Option` because objects written before this field existed lack it and
/// must still decode; skipped when `None` so such an object re-serialises