swarm-matrix-ctl: mint the swarm's own appservice registration
The swarm gets an appservice identity of its own, separate from each hive's `hyperhive` registration. `swarm-matrix-ctl appservice render` mints its tokens inside the matrix container when they are absent and renders the registration tuwunel loads; `appservice publish` writes its as_token to `swarm/controller/swarm-controller/matrix/appservice-token`, the one kind no hive's policy grants. The homeserver calls move out of swarm-matrix-ctl into swarm-matrix-client, with a `whoami`, so swarm-controller can mint agents' accounts through the same pinned device id instead of a copy of them.
This commit is contained in:
parent
cb176c7be7
commit
89aff8d613
10 changed files with 523 additions and 23 deletions
|
|
@ -7,18 +7,19 @@
|
|||
//! identity plumbing to add one action, so the next thing that has to run in
|
||||
//! here is a verb below, not a new crate.
|
||||
//!
|
||||
//! Today that is one verb, [`mint`]: publish the appservice sender account's
|
||||
//! homeserver access token to the swarm's secret store, once.
|
||||
//! [`mint`] publishes a hive's appservice sender token to the swarm's secret
|
||||
//! store, once. [`appservice`] mints the **swarm's** own appservice
|
||||
//! registration and publishes its token for `swarm-controller`.
|
||||
//!
|
||||
//! It lives in the container because the appservice `as_token` that authorises
|
||||
//! the mint is *already* there — the registration tuwunel loads is bind-mounted
|
||||
//! in — so no second holder of that secret is created.
|
||||
//!
|
||||
//! 🩸 **A secret is a path, never a value.** The only identifier any verb here
|
||||
//! logs is the store path; see `homeserver`'s module doc for the same rule
|
||||
//! logs is the store path; see `swarm_matrix_client`'s module doc for the same rule
|
||||
//! applied to error messages.
|
||||
|
||||
mod homeserver;
|
||||
mod appservice;
|
||||
mod mint;
|
||||
mod registration;
|
||||
|
||||
|
|
@ -44,6 +45,20 @@ enum Command {
|
|||
/// no flags, because a systemd `Environment=` block is what a nix module
|
||||
/// can render and a command line full of paths is not.
|
||||
Mint,
|
||||
/// The swarm's own appservice registration, whose sender is the
|
||||
/// homeserver's admin account. Configured by `MATRIX_APPSERVICE_*`.
|
||||
#[command(subcommand)]
|
||||
Appservice(Appservice),
|
||||
}
|
||||
|
||||
#[derive(Debug, Subcommand)]
|
||||
enum Appservice {
|
||||
/// Mint the tokens when absent and render the registration tuwunel loads.
|
||||
/// Local only: it runs before the homeserver and must not need a network.
|
||||
Render,
|
||||
/// Write the rendered `as_token` to the swarm secret store when the
|
||||
/// store's copy differs.
|
||||
Publish,
|
||||
}
|
||||
|
||||
#[tokio::main]
|
||||
|
|
@ -57,6 +72,8 @@ async fn main() -> Result<()> {
|
|||
|
||||
match Cli::parse().command {
|
||||
Command::Mint => mint::run().await,
|
||||
Command::Appservice(Appservice::Render) => appservice::render(),
|
||||
Command::Appservice(Appservice::Publish) => appservice::publish().await,
|
||||
}
|
||||
}
|
||||
|
||||
|
|
@ -80,6 +97,25 @@ mod tests {
|
|||
|
||||
/// The control: without it the case above passes on a parser that accepts
|
||||
/// anything.
|
||||
/// The two units name these verbs, same reason as the test above.
|
||||
#[test]
|
||||
fn the_appservice_verbs_are_spelled_the_way_the_units_invoke_them() {
|
||||
let cli =
|
||||
Cli::try_parse_from(["swarm-matrix-ctl", "appservice", "render"]).expect("a verb");
|
||||
assert!(matches!(
|
||||
cli.command,
|
||||
Command::Appservice(Appservice::Render)
|
||||
));
|
||||
let cli =
|
||||
Cli::try_parse_from(["swarm-matrix-ctl", "appservice", "publish"]).expect("a verb");
|
||||
assert!(matches!(
|
||||
cli.command,
|
||||
Command::Appservice(Appservice::Publish)
|
||||
));
|
||||
Cli::try_parse_from(["swarm-matrix-ctl", "appservice"])
|
||||
.expect_err("a sub-verb is required");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn an_unknown_verb_is_refused() {
|
||||
Cli::try_parse_from(["swarm-matrix-ctl", "conjure"])
|
||||
|
|
|
|||
Loading…
Reference in a new issue