docs: the swarm mints agent forge tokens; hive-c0re and tea-login no longer do
credentials.md gains the forge-token row and drops the claim that the forge token never passes through the store. setup.md says plainly that an agent spawned on the hive alone, ruth's bootstrap included, now gets no forge user from anything. CLI references regenerated. Refs #3782
This commit is contained in:
parent
6d0c30ade2
commit
abc942cff3
8 changed files with 96 additions and 43 deletions
|
|
@ -29,7 +29,7 @@ at boot. Useful for recovery, ad-hoc re-provisioning, or fixing a single
|
|||
agent without bouncing the daemon.
|
||||
|
||||
```bash
|
||||
hivectl forge create-user iris # provision (or refresh) forge account for agent `iris`
|
||||
hivectl forge create-user iris # refused: `iris` is an agent; use `swarmctl agent mint-forge-token iris`
|
||||
hivectl forge create-user mara # create forge account for a human user; prints token to stdout
|
||||
hivectl forge create-user mara --password hunter2 # set a web-login password
|
||||
hivectl forge create-user mara --password-stdin # read password from stdin (safer for scripting)
|
||||
|
|
@ -40,8 +40,9 @@ hivectl forge reconcile-config iris --verbose # include the full diff, not
|
|||
```
|
||||
|
||||
- For **agents** (name has a state dir under `/var/lib/hyperhive/agents/`):
|
||||
`create-user` persists the token to `<state>/forge-token`. Re-running refreshes the
|
||||
token (idempotent — scope always matches current `TOKEN_SCOPES`).
|
||||
`create-user` refuses. swarm-controller mints an agent's token into
|
||||
the swarm secret store; `swarmctl agent mint-forge-token <agent>` checks
|
||||
and, if needed, re-mints it.
|
||||
- For **non-agents** (humans): creates the account and prints the token to
|
||||
stdout, creating no state dir. Re-running after account already exists
|
||||
re-mints the token and prints it again — safe for password resets.
|
||||
|
|
|
|||
Loading…
Reference in a new issue