docs: the swarm mints agent forge tokens; hive-c0re and tea-login no longer do
credentials.md gains the forge-token row and drops the claim that the forge token never passes through the store. setup.md says plainly that an agent spawned on the hive alone, ruth's bootstrap included, now gets no forge user from anything. CLI references regenerated. Refs #3782
This commit is contained in:
parent
6d0c30ade2
commit
abc942cff3
8 changed files with 96 additions and 43 deletions
|
|
@ -25,14 +25,15 @@ operator has to place, and where.
|
|||
### 1 · Forge
|
||||
|
||||
```bash
|
||||
# Provision (or refresh) ruth's own forge account — do this first. Ruth's
|
||||
# bootstrap bypasses the normal spawn-approval flow ("Spawn sub-agents"
|
||||
# below), so unlike every other agent it does not get its forge account
|
||||
# auto-provisioned — this manual step is still load-bearing.
|
||||
hivectl forge create-user ruth
|
||||
|
||||
# Sub-agents spawned later (via the approval flow in "Spawn sub-agents")
|
||||
# get their forge accounts auto-provisioned — nothing to run here for them.
|
||||
# hive-c0re no longer creates agent forge users or mints agent tokens:
|
||||
# swarm-controller does, for agents created at swarm level
|
||||
# (`swarmctl agent create`), and stores the token in the swarm secret store,
|
||||
# where the agent fetches it. An agent that only ever existed on this hive —
|
||||
# ruth's bootstrap, or the hive's own spawn-approval flow — gets no forge
|
||||
# user from anything yet. Create that user in the forge's admin UI; once the
|
||||
# agent has a store identity (`swarmctl agent mint-identity`), swarm-controller
|
||||
# mints its token within five minutes, or at once with:
|
||||
swarmctl agent mint-forge-token ruth
|
||||
```
|
||||
|
||||
Swarm SSO creates the human operator's own forge account instead of
|
||||
|
|
@ -267,7 +268,9 @@ See [`tools/hivectl.md`](../tools/hivectl.md) for every `hivectl` verb.
|
|||
<!-- vale write-good.Passive = NO -->
|
||||
|
||||
- **No forge admin token is stored in any agent state dir.** Agents
|
||||
hold a regular agent token in their `forge-token` file; sensitive
|
||||
hold a regular agent token, fetched from the swarm secret store into
|
||||
`/run/hive-agent-forge-token/token` (or, for an agent without a store
|
||||
identity, the `forge-token` file hive-c0re wrote before); sensitive
|
||||
creds (the core token) live on the host.
|
||||
- All config changes (forge PRs on `agent-configs/<name>`) go through
|
||||
operator approval — agents can't unilaterally rebuild containers, by design.
|
||||
|
|
|
|||
Loading…
Reference in a new issue