matrix: the agent's daemon pulls its linked accounts from bao itself
hive-matrix-daemon now learns which external matrix accounts it has from the swarm secret store, under the agent's own certificate, and the hive push chain for matrix is gone. The daemon lists swarm/agents/<agent>/matrix/ (the `list` its policy grants on its own metadata subtree), reads each account's homeserver from its credential, and brings the accounts up with their tokens from the store. Every two minutes it lists again and exits with 75 when the set of linked accounts changed; the unit restarts on 75 without counting a failure. A listed name whose credential reads as absent is skipped and logged once. At start it removes the matrix-token-<a> / matrix-account-<a>.json pairs a hive delivered (a sidecar marks a pair as delivered; a declared tokenFile keeps its token). Removed: CredentialNotice and the $SWARM.credential.* subject and NATS grant, the controller's publish and its queue precondition on the PUT route, hive-c0re's credential subscription arm and workers/credential.rs, priv_client::write_agent_matrix_token, hive-priv's WriteAgentMatrixToken and its helpers, and the daemon's state-dir account discovery. Kept: WriteAgentGithubToken and the external-forge path (WriteAgentExtraForgeAccount, extra_forges.rs) are untouched, and a declared matrixAccounts tokenFile is still read when the store has no token for that account. Refs #4348
This commit is contained in:
parent
e04616eb70
commit
97fb76ce99
22 changed files with 553 additions and 813 deletions
|
|
@ -14,10 +14,9 @@
|
|||
}:
|
||||
let
|
||||
userName = config.services.hyperhive.agent.user.name;
|
||||
# This agent's own state dir, where a hive used to write the `main`
|
||||
# account's token (`matrix-token`, now the store's fallback) and the
|
||||
# daemon keeps its matrix-sdk store. Shared by the `main` account entry
|
||||
# below and the path-watcher glob at the bottom of this file.
|
||||
# This agent's own state dir: `main`'s fallback token file (`matrix-token`)
|
||||
# and the daemon's matrix-sdk stores. Shared by the `main` account entry below
|
||||
# and the path-watcher glob at the bottom of this file.
|
||||
stateDir = "/agents/${userName}/state";
|
||||
accounts = config.services.hyperhive.agent.matrixAccounts;
|
||||
# This agent's own identity at the swarm secret store (./bao.nix). The daemon
|
||||
|
|
@ -390,6 +389,11 @@ in
|
|||
# non-zero exit, which `on-failure` already restarts.
|
||||
Restart = "on-failure";
|
||||
RestartSec = 5;
|
||||
# The daemon exits 75 (`ACCOUNTS_CHANGED_EXIT` in
|
||||
# hive-matrix-mcp/src/main.rs) when the store's linked accounts change:
|
||||
# a clean exit that must still restart it onto the new set.
|
||||
RestartForceExitStatus = "75";
|
||||
SuccessExitStatus = "75";
|
||||
User = userName;
|
||||
Group = userName;
|
||||
}
|
||||
|
|
@ -416,18 +420,16 @@ in
|
|||
timerConfig.OnUnitInactiveSec = "5min";
|
||||
};
|
||||
|
||||
# Re-fire the daemon when the matrix token appears (a token
|
||||
# file: an extra account the hive delivers, or a `main` from before the
|
||||
# swarm minted it). Without this
|
||||
# Re-fire the daemon when a matrix token file appears (a declared
|
||||
# `tokenFile`, or a `main` from before the swarm minted it). Without this
|
||||
# the daemon would exit 0 silently on first boot and the MCP
|
||||
# would have no backend until next restart. See
|
||||
# `docs/agent-lifecycle/persistence.md` (same section as above).
|
||||
systemd.paths.hive-matrix-daemon = lib.mkIf matrixEnabled {
|
||||
description = "trigger hive-matrix-daemon when a matrix token appears";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
# `matrix-token*` (not just `matrix-token`) so a secondary
|
||||
# multi-account token (e.g. `matrix-token-ccc`) landing also
|
||||
# re-fires the daemon to pick up the freshly-provisioned account.
|
||||
# `matrix-token*` (not just `matrix-token`) so a declared secondary
|
||||
# token file (e.g. `matrix-token-ccc`) landing also re-fires the daemon.
|
||||
#
|
||||
# ⚠️ This agent's own state dir, not a glob over `/agents/*/`. Every
|
||||
# agent's state dir is visible from inside every container, so a
|
||||
|
|
|
|||
Loading…
Reference in a new issue