matrix: the agent's daemon pulls its linked accounts from bao itself
hive-matrix-daemon now learns which external matrix accounts it has from the swarm secret store, under the agent's own certificate, and the hive push chain for matrix is gone. The daemon lists swarm/agents/<agent>/matrix/ (the `list` its policy grants on its own metadata subtree), reads each account's homeserver from its credential, and brings the accounts up with their tokens from the store. Every two minutes it lists again and exits with 75 when the set of linked accounts changed; the unit restarts on 75 without counting a failure. A listed name whose credential reads as absent is skipped and logged once. At start it removes the matrix-token-<a> / matrix-account-<a>.json pairs a hive delivered (a sidecar marks a pair as delivered; a declared tokenFile keeps its token). Removed: CredentialNotice and the $SWARM.credential.* subject and NATS grant, the controller's publish and its queue precondition on the PUT route, hive-c0re's credential subscription arm and workers/credential.rs, priv_client::write_agent_matrix_token, hive-priv's WriteAgentMatrixToken and its helpers, and the daemon's state-dir account discovery. Kept: WriteAgentGithubToken and the external-forge path (WriteAgentExtraForgeAccount, extra_forges.rs) are untouched, and a declared matrixAccounts tokenFile is still read when the store has no token for that account. Refs #4348
This commit is contained in:
parent
e04616eb70
commit
97fb76ce99
22 changed files with 553 additions and 813 deletions
|
|
@ -207,22 +207,8 @@ async fn drain_swarm_events(
|
|||
return;
|
||||
}
|
||||
};
|
||||
// Also this hive's own, and for a second reason on top of the deploy
|
||||
// subject's: the payload names an agent in *this* hive's state dir, so a
|
||||
// notice for another hive is not merely noise, it is unactionable here.
|
||||
let credential_subject = swarm_queue_client::credential_subject(&hive);
|
||||
let mut credential_sub = match client.subscribe(credential_subject.clone()).await {
|
||||
Ok(sub) => sub,
|
||||
Err(e) => {
|
||||
tracing::warn!(
|
||||
subject = %credential_subject, error = %e,
|
||||
"swarm events: subscribe failed; this hive will not hear credential notices"
|
||||
);
|
||||
return;
|
||||
}
|
||||
};
|
||||
tracing::info!(
|
||||
%subject, %deploy_subject, %credential_subject,
|
||||
%subject, %deploy_subject,
|
||||
"swarm events: listening"
|
||||
);
|
||||
|
||||
|
|
@ -254,13 +240,6 @@ async fn drain_swarm_events(
|
|||
};
|
||||
handle_deploy_request(&coord, &msg.payload).await;
|
||||
}
|
||||
msg = credential_sub.next() => {
|
||||
let Some(msg) = msg else {
|
||||
tracing::warn!(subject = %credential_subject, "swarm events: credential subscription closed");
|
||||
return;
|
||||
};
|
||||
handle_credential_notice(&hive, &msg.payload).await;
|
||||
}
|
||||
_ = shutdown.changed() => {
|
||||
tracing::info!("swarm events: shutdown signal received");
|
||||
return;
|
||||
|
|
@ -274,39 +253,6 @@ async fn drain_swarm_events(
|
|||
///
|
||||
/// A payload that will not decode is worth a `warn`: the controller and this
|
||||
/// end share one type, so a decode failure means they disagree about it.
|
||||
/// Deliver the credential a [`swarm_queue_client::CredentialNotice`] names.
|
||||
///
|
||||
/// `hive` doubles as the cert-auth role this hive logs into the store as:
|
||||
/// `glue-bao-tls.nix` mints the client certificate with the hive name as its
|
||||
/// CN, and a bao cert role matches on CN — so the two share a name by
|
||||
/// construction rather than by convention.
|
||||
///
|
||||
/// ⚠️ Nothing here can log the secret, and that is structural rather than
|
||||
/// careful: the notice carries only names, and `deliver` writes the value
|
||||
/// without returning it.
|
||||
async fn handle_credential_notice(hive: &str, payload: &[u8]) {
|
||||
let notice: swarm_queue_client::CredentialNotice = match serde_json::from_slice(payload) {
|
||||
Ok(notice) => notice,
|
||||
Err(e) => {
|
||||
tracing::warn!(error = %e, "swarm events: undecodable credential notice");
|
||||
return;
|
||||
}
|
||||
};
|
||||
if let Err(e) = crate::workers::credential::deliver(¬ice, hive).await {
|
||||
// Warn rather than retry: the controller republishes, and a hive that
|
||||
// spun here would hold the queue task off its other two subjects.
|
||||
tracing::warn!(
|
||||
agent = %notice.agent, account = %notice.account, error = ?e,
|
||||
"swarm events: credential delivery failed"
|
||||
);
|
||||
return;
|
||||
}
|
||||
tracing::info!(
|
||||
agent = %notice.agent, account = %notice.account,
|
||||
"swarm events: credential delivered"
|
||||
);
|
||||
}
|
||||
|
||||
async fn handle_deploy_request(
|
||||
coord: &std::sync::Arc<crate::coordinator::Coordinator>,
|
||||
payload: &[u8],
|
||||
|
|
|
|||
Loading…
Reference in a new issue