hivectl, hive-c0re: remove dead matrix create-user/promote-user/reset-password
Human matrix accounts come from SSO, not hivectl. Matrix homeserver admin will come from authelia's admins group (sync tracked in #4585); password reset moves to swarm level (#4798). promote-user and reset-password were already broken from the hive: the hive's sender account has no admin sender to call the admin room with, only the swarm's does. Removes the three hivectl matrix verbs, their HostRequest variants, their hive-c0re handlers, and the admin-room helpers (discover room id, send-and-poll, event-id extraction, password/success parsing) that only they used. sync-admin and invite are unchanged. Refs #4585
This commit is contained in:
parent
69ae23f801
commit
93bbec015f
12 changed files with 37 additions and 748 deletions
|
|
@ -286,11 +286,12 @@ hivectl matrix sync-admin
|
|||
# Invite the operator to the hive Space (and optionally to rooms)
|
||||
hivectl matrix invite mara
|
||||
hivectl matrix invite @mara:yourserver --room '#hive-chat:yourserver'
|
||||
|
||||
# Promote the operator to homeserver admin if needed
|
||||
hivectl matrix promote-user mara
|
||||
```
|
||||
|
||||
The operator's own matrix account comes from SSO, not `hivectl` — matrix
|
||||
homeserver admin should eventually come from membership in authelia's
|
||||
`admins` group; nobody has built that sync yet.
|
||||
|
||||
ruth's own matrix account comes from the swarm, like every agent's:
|
||||
`swarm-controller` creates it within five minutes of her holding a store
|
||||
identity (step 1), and her matrix daemon reads its token from the store.
|
||||
|
|
|
|||
|
|
@ -130,8 +130,7 @@ a token.
|
|||
so the sibling credentials are invisible to it. The `.yaml` suffix on
|
||||
the credential id is what makes this work.
|
||||
5. **hive-c0re** reads the appservice token and creates its own
|
||||
`@hive-<hive>:` account, and the accounts an operator asks for with
|
||||
`hivectl matrix create-user`. It never mints the token itself: the value
|
||||
`@hive-<hive>:` account. It never mints the token itself: the value
|
||||
has to be the one the rendered registration names, and only the nix
|
||||
side writes that.
|
||||
6. **Agents' accounts aren't this hive's.** `swarm-controller` creates each
|
||||
|
|
@ -199,15 +198,12 @@ being the rooms' own creator at power level 100 — there is no homeserver
|
|||
admin in any of it, and no Synapse admin API to reach for either, since
|
||||
tuwunel has none.
|
||||
|
||||
Two operations need an admin **sender**: `hivectl matrix promote-user`
|
||||
and `hivectl matrix reset-password`. Both are `!admin …` messages into
|
||||
`#admins:<server_name>`, and tuwunel only treats a message as a command
|
||||
when its sender is already an admin. They're swarm-level operations,
|
||||
rehomed to the swarm tier rather than granted here; from the hive,
|
||||
`@hive-<hive>:` has no admin sender to make that call with, so both get the
|
||||
admin room's refusal rather than an over-privileged credential that
|
||||
every other call site would also carry. The swarm's own sender is the
|
||||
admin they need; moving them there is separate work.
|
||||
Promoting a user to homeserver admin and resetting a password both need an
|
||||
admin **sender**: `!admin …` messages into `#admins:<server_name>`, and
|
||||
tuwunel only treats a message as a command when its sender is already an
|
||||
admin. `@hive-<hive>:` has no admin sender to make that call with. They're
|
||||
swarm-level operations: matrix admin should eventually come from
|
||||
membership in authelia's `admins` group; nobody has built that sync yet.
|
||||
|
||||
<details><summary>Upgrading a hive that shared one sender account with every other hive</summary>
|
||||
|
||||
|
|
|
|||
|
|
@ -8,10 +8,7 @@ This document contains the help content for the `hivectl` command-line program.
|
|||
* [`hivectl forge`↴](#hivectl-forge)
|
||||
* [`hivectl forge reconcile-config`↴](#hivectl-forge-reconcile-config)
|
||||
* [`hivectl matrix`↴](#hivectl-matrix)
|
||||
* [`hivectl matrix create-user`↴](#hivectl-matrix-create-user)
|
||||
* [`hivectl matrix sync-admin`↴](#hivectl-matrix-sync-admin)
|
||||
* [`hivectl matrix promote-user`↴](#hivectl-matrix-promote-user)
|
||||
* [`hivectl matrix reset-password`↴](#hivectl-matrix-reset-password)
|
||||
* [`hivectl matrix invite`↴](#hivectl-matrix-invite)
|
||||
* [`hivectl github`↴](#hivectl-github)
|
||||
* [`hivectl github set-token`↴](#hivectl-github-set-token)
|
||||
|
|
@ -142,33 +139,11 @@ Manual entry point to the same idempotent provisioning c0re runs at boot — for
|
|||
|
||||
###### **Subcommands:**
|
||||
|
||||
* `create-user` — Create a matrix account for a person or other non-agent `<name>` and print its access token to stdout
|
||||
* `sync-admin` — Provision (or re-provision) the matrix appservice's sender account
|
||||
* `promote-user` — Promote a matrix user to homeserver admin
|
||||
* `reset-password` — Reset a matrix user's password via the admin API
|
||||
* `invite` — Invite a matrix user to the hive Space, or a specific room with `--room`. Idempotent
|
||||
|
||||
|
||||
|
||||
## `hivectl matrix create-user`
|
||||
|
||||
Create a matrix account for a person or other non-agent `<name>` and print its access token to stdout.
|
||||
|
||||
Refuses an agent's name: its account comes from the swarm (`swarm-controller` creates it and stores its token where the agent reads it). Set a password to enable matrix web-client login (otherwise it uses a random throwaway).
|
||||
|
||||
**Usage:** `hivectl matrix create-user [OPTIONS] <NAME>`
|
||||
|
||||
###### **Arguments:**
|
||||
|
||||
* `<NAME>` — Matrix localpart of a non-agent account — `mara`, `damocles`, etc
|
||||
|
||||
###### **Options:**
|
||||
|
||||
* `--password <PASSWORD>` — Set the account password to this string instead of a random throwaway. Use this for operator accounts that need to log into matrix web clients via `m.login.password`. Mutually exclusive with `--password-stdin`. WARNING: the password is visible in shell history + process listings; prefer `--password-stdin` for anything sensitive
|
||||
* `--password-stdin` — Read the password from stdin (single line, trailing newline stripped) instead of an inline flag. Mutually exclusive with `--password`
|
||||
|
||||
|
||||
|
||||
## `hivectl matrix sync-admin`
|
||||
|
||||
Provision (or re-provision) the matrix appservice's sender account.
|
||||
|
|
@ -179,32 +154,6 @@ Runs automatically on startup; run manually to recover a missing access token.
|
|||
|
||||
|
||||
|
||||
## `hivectl matrix promote-user`
|
||||
|
||||
Promote a matrix user to homeserver admin
|
||||
|
||||
**Usage:** `hivectl matrix promote-user <NAME>`
|
||||
|
||||
###### **Arguments:**
|
||||
|
||||
* `<NAME>` — Matrix localpart of the user to promote (for example `argus`)
|
||||
|
||||
|
||||
|
||||
## `hivectl matrix reset-password`
|
||||
|
||||
Reset a matrix user's password via the admin API.
|
||||
|
||||
Persists the new password so a later `create-user` can re-login.
|
||||
|
||||
**Usage:** `hivectl matrix reset-password <NAME>`
|
||||
|
||||
###### **Arguments:**
|
||||
|
||||
* `<NAME>` — Matrix localpart of the account to reset (for example `argus`)
|
||||
|
||||
|
||||
|
||||
## `hivectl matrix invite`
|
||||
|
||||
Invite a matrix user to the hive Space, or a specific room with `--room`. Idempotent
|
||||
|
|
|
|||
|
|
@ -50,31 +50,19 @@ Manual entry to the same idempotent matrix provisioning flow
|
|||
running (`services.hyperhive.deploy.matrix.enable = true`).
|
||||
|
||||
```bash
|
||||
hivectl matrix create-user mara # create matrix account for a human; prints access_token to stdout
|
||||
hivectl matrix create-user mara --password hunter2 # set a client-login password
|
||||
hivectl matrix sync-admin # provision / refresh the appservice's sender account
|
||||
hivectl matrix promote-user mara # promote an existing matrix user to homeserver admin
|
||||
hivectl matrix reset-password iris # generate and set a new random password for `iris`; prints it
|
||||
hivectl matrix invite mara # invite a user to the hive Space
|
||||
hivectl matrix invite @mara:server --room '#hive-chat:server' # ...or to a specific room/alias
|
||||
```
|
||||
|
||||
- `create-user`: for people and other non-agent accounts. It refuses
|
||||
an agent's name: `swarm-controller` creates an agent's account and
|
||||
stores its token where the agent's daemon reads it.
|
||||
Human matrix accounts come from SSO, not `hivectl`; matrix homeserver
|
||||
admin should eventually come from membership in authelia's `admins`
|
||||
group; nobody has built that sync yet.
|
||||
|
||||
- `sync-admin`: ensures this hive's appservice sender account
|
||||
(`@hive-<hive>:<server_name>`, one per hive) exists
|
||||
(the account `hive-c0re` provisions rooms with). Token persisted to the
|
||||
access token path. Safe to run again — idempotent.
|
||||
- `promote-user`: promotes an already-registered user to homeserver
|
||||
admin by an `!admin` command in `#admins`. ⚠️ Needs an admin **sender**,
|
||||
which `@hive-<hive>:` isn't — promotion is a swarm-level operation, rehomed to
|
||||
the swarm tier rather than granted here, so it has no admin sender to
|
||||
call it with from the hive.
|
||||
- `reset-password`: asks the admin room to set a new random
|
||||
password and prints it to stdout. ⚠️ Same admin-**sender** requirement,
|
||||
and the same swarm-level rehoming, so it's unavailable from the hive
|
||||
too. Useful if an agent or human lost credentials.
|
||||
- `invite`: invites a matrix user (full `@user:server` or a bare
|
||||
localpart, qualified with the homeserver's `server_name`) to the hive
|
||||
Space by default, or to a `--room` id / `#alias`. Uses the sender
|
||||
|
|
|
|||
Loading…
Reference in a new issue