parent
bf81241744
commit
9545151b8d
10 changed files with 62 additions and 112 deletions
|
|
@ -123,7 +123,7 @@ the agent user and sets `0751`. The container has no user namespace, so
|
|||
that uid is the host inode's owner. Don't add a host-side chown or chmod:
|
||||
two owners of one path revert each other. Until the container activates,
|
||||
the dir is `0751 root`: nothing but root can plant a socket in it, and a
|
||||
legacy root-run harness can still bind.
|
||||
root-run harness can still bind.
|
||||
|
||||
<!-- vale write-good.Passive = YES -->
|
||||
|
||||
|
|
|
|||
|
|
@ -100,10 +100,7 @@ its own store identity so credentials never pass through a hive at all.
|
|||
agent and service stanzas above) because a hive's own path names it, so
|
||||
scoping to the reader's own name costs nothing and drifts nowhere. That only
|
||||
holds if a credential that must be one-per-hive is actually stored under the
|
||||
hive kind — the matrix sender token was originally published to
|
||||
`swarm/services/matrix/sender-token`, under the **service** kind, and so was
|
||||
readable by every hive though it belonged to only one. Making it per-hive meant
|
||||
moving its path under the hive kind, not narrowing the service stanza's grant.
|
||||
hive kind.
|
||||
**A credential that must be one-per-hive goes under `Kind::Hive`**; putting it
|
||||
under `Kind::Service` and expecting the grant to scope it — that's the mistake
|
||||
this note exists to stop.
|
||||
|
|
@ -296,7 +293,7 @@ known operations; there is no arbitrary command pass-through:
|
|||
| `DaemonReload` | `systemctl daemon-reload` |
|
||||
| `RunForgeAdmin` | `nixos-container run hive-forge -- runuser -u forgejo -- forgejo admin <args>` |
|
||||
| `ControlInfraContainer` | `systemctl <action> container@<container>.service` — the `InfraContainer` enum is the allowlist, and serde rejects unknown names at the wire boundary (`hive-c0re` has no variant, so no request can name it) |
|
||||
| `SyncAgentTmpfiles` | legacy: unlink `/etc/tmpfiles.d/hyperhive-agents.conf` and return `Ok`; kept one release for an older hive-c0re |
|
||||
| `SyncAgentTmpfiles` | unlink `/etc/tmpfiles.d/hyperhive-agents.conf` and return `Ok` |
|
||||
| `SetAgentPaused` | create / remove the `<state>/<name>/harness/paused` marker that parks an agent's turn loop |
|
||||
| `WriteAgentGithubToken` | write `0600` `github-token` into agent state dir |
|
||||
| `RegisterCiRunner` | write `/run/hive-ci/runner-token` (host path, root-owned) then `systemctl --machine=hive-ci restart gitea-runner-hive.service`. Only the registration token crosses; the forge admin token never enters the container |
|
||||
|
|
|
|||
Loading…
Reference in a new issue