docs: the swarm mints agent forge tokens; hive-c0re and tea-login no longer do
credentials.md gains the forge-token row and drops the claim that the forge token never passes through the store. setup.md says plainly that an agent spawned on the hive alone, ruth's bootstrap included, now gets no forge user from anything. CLI references regenerated. Refs #3782
This commit is contained in:
parent
6d0c30ade2
commit
abc942cff3
8 changed files with 96 additions and 43 deletions
|
|
@ -17,7 +17,9 @@ each agent on relevant activity.
|
|||
|
||||
Two scope sets live in `hive-c0re::forge`:
|
||||
|
||||
**`TOKEN_SCOPES`** (per-agent tokens):
|
||||
**`TOKEN_SCOPES`** (per-agent tokens, and `hivectl forge create-user`
|
||||
accounts). swarm-controller mints agent tokens with a byte-identical copy,
|
||||
`forge::agent_token::AGENT_TOKEN_SCOPES`, pinned by a test:
|
||||
|
||||
| Scope | Why |
|
||||
| -------------------- | ------------------------------------------------------------------------------------------------------- |
|
||||
|
|
@ -46,13 +48,19 @@ hive-c0re to re-mint with the new scopes.
|
|||
|
||||
## Per-agent forge accounts
|
||||
|
||||
Each agent gets its own Forgejo user + access token, provisioned at
|
||||
boot by `hive-c0re::forge`. The provisioning flow is idempotent:
|
||||
`hive-c0re::forge` reuses existing accounts + tokens, so container destroy/recreate
|
||||
doesn't lose forge identity. It writes the token to
|
||||
`<state>/forge-token` (one line, no trailing newline) inside the
|
||||
agent container so `hive-forge` CLI + `forge_notify` poller can
|
||||
read it without touching c0re's host-side credential store.
|
||||
Each agent gets its own Forgejo user and access token. swarm-controller
|
||||
creates the user when it creates the agent, and mints one token named
|
||||
`swarm-agent` with the admin API into the swarm secret store at
|
||||
`swarm/agents/<agent>/forge-token`. A pass at start and every five minutes
|
||||
re-mints any agent's token that's missing or no longer matches the forge;
|
||||
a rotation deletes the old `swarm-agent` token first, so each agent holds at
|
||||
most one. The agent fetches the token under its own store certificate into
|
||||
`/run/hive-agent-forge-token/token` (`nix/agent-modules/forge-token.nix`),
|
||||
and `hive-forge`, the git credential helper, the `forge_notify` poller and
|
||||
the avatar sync read it from there, falling back to `<state>/forge-token`,
|
||||
the file hive-c0re wrote before. hive-c0re no longer creates agent users or
|
||||
mints agent tokens; the `hyperhive-<unix-seconds>` tokens it minted stay on
|
||||
the forge until removed.
|
||||
|
||||
Two things live in the `agent-configs` Forgejo organization:
|
||||
|
||||
|
|
@ -162,7 +170,7 @@ The poller starts disabled and stays that way for any of:
|
|||
|
||||
- `HIVE_FORGE_URL` not set (no forge configured for this hive), or
|
||||
not parseable as a URL.
|
||||
- `<state>/forge-token` missing or empty (agent has no forge
|
||||
- no token in `$HIVE_FORGE_TOKEN_FILE` or `<state>/forge-token` (agent has no forge
|
||||
account — pre-provisioning or destroy-without-purge race).
|
||||
- Initial client construction fails (the typed `forgejo-api` client
|
||||
for the API calls, or the plain reqwest client kept for the
|
||||
|
|
|
|||
Loading…
Reference in a new issue