hive-c0re: stop minting agents' matrix accounts
The swarm mints each agent's `main` account now, so the hive's own mint goes: `ensure_user_for`, `finish_user_provisioning`, `sync_agent`, `sync_agent_standalone`, `token_path`, `legacy_password_path`, `auto_reset_password` and `token_file_present`, and the calls from the startup sweep and the rebuild bookkeeping. Both mints pinned the device `hyperhive-<agent>`, so leaving this one would have each re-login kill the other's token. `hivectl matrix create-user` refuses an agent's name and says where its account comes from. Everything that still uses the hive's appservice token stays: the hive's own account, the Space and chat room, and operator accounts.
This commit is contained in:
parent
ab153bda2f
commit
89a5dd752c
6 changed files with 61 additions and 351 deletions
|
|
@ -142,7 +142,7 @@ Manual entry point to the same idempotent provisioning c0re runs at boot — for
|
|||
|
||||
###### **Subcommands:**
|
||||
|
||||
* `create-user` — Create or refresh the matrix account + access token for `<name>`
|
||||
* `create-user` — Create a matrix account for a person or other non-agent `<name>` and print its access token to stdout
|
||||
* `sync-admin` — Provision (or re-provision) the matrix appservice's sender account
|
||||
* `promote-user` — Promote a matrix user to homeserver admin
|
||||
* `reset-password` — Reset a matrix user's password via the admin API
|
||||
|
|
@ -152,15 +152,15 @@ Manual entry point to the same idempotent provisioning c0re runs at boot — for
|
|||
|
||||
## `hivectl matrix create-user`
|
||||
|
||||
Create or refresh the matrix account + access token for `<name>`.
|
||||
Create a matrix account for a person or other non-agent `<name>` and print its access token to stdout.
|
||||
|
||||
For an existing agent, persists the token to its state dir; for a human/other account, prints the access token to stdout. Set a password to enable matrix web-client login (otherwise it uses a random throwaway).
|
||||
Refuses an agent's name: its account comes from the swarm (`swarm-controller` creates it and stores its token where the agent reads it). Set a password to enable matrix web-client login (otherwise it uses a random throwaway).
|
||||
|
||||
**Usage:** `hivectl matrix create-user [OPTIONS] <NAME>`
|
||||
|
||||
###### **Arguments:**
|
||||
|
||||
* `<NAME>` — Matrix localpart. For agents: the container/agent name. For humans: any matrix localpart — `mara`, `damocles`, etc
|
||||
* `<NAME>` — Matrix localpart of a non-agent account — `mara`, `damocles`, etc
|
||||
|
||||
###### **Options:**
|
||||
|
||||
|
|
|
|||
|
|
@ -50,7 +50,6 @@ Manual entry to the same idempotent matrix provisioning flow
|
|||
running (`services.hyperhive.deploy.matrix.enable = true`).
|
||||
|
||||
```bash
|
||||
hivectl matrix create-user iris # provision (or re-provision) matrix account for agent `iris`
|
||||
hivectl matrix create-user mara # create matrix account for a human; prints access_token to stdout
|
||||
hivectl matrix create-user mara --password hunter2 # set a client-login password
|
||||
hivectl matrix sync-admin # provision / refresh the appservice's sender account
|
||||
|
|
@ -60,9 +59,9 @@ hivectl matrix invite mara # invite a user to the hive Space
|
|||
hivectl matrix invite @mara:server --room '#hive-chat:server' # ...or to a specific room/alias
|
||||
```
|
||||
|
||||
- `create-user`: for agents, persists the `access_token` to
|
||||
`<state>/matrix-token`. Skips registration when the file already
|
||||
exists — delete it first to force re-registration.
|
||||
- `create-user`: for people and other non-agent accounts. It refuses
|
||||
an agent's name: `swarm-controller` creates an agent's account and
|
||||
stores its token where the agent's daemon reads it.
|
||||
- `sync-admin`: ensures this hive's appservice sender account
|
||||
(`@hive-<hive>:<server_name>`, one per hive) exists
|
||||
(the account `hive-c0re` provisions rooms with). Token persisted to the
|
||||
|
|
|
|||
Loading…
Reference in a new issue