agent: fetch this agent's own swarm-queue credential from the store
Every agent on a hive authenticates to the swarm queue with the same hive-scoped OIDC client, so at the auth callout one agent is indistinguishable from its co-hived neighbours. The commit before this one mints a secret per agent at swarm level into secret/swarm/agents/<agent>/queue; nothing read it. Read it here, and read it from the container itself. A hive courier in the path would be the hive vouching for which agent this is, which is the property a per-agent credential exists to remove -- so the agent logs in to the store with the certificate hive-agent-bao-identity already proves it can log in with, and reads its own path. The store certificate is for reaching the store and nothing else: what the new unit writes to /run is the secret it read back, and nothing hands a BAO_CLIENT_* path to anything queue-shaped. The read needs no policy change. render_agent grants read on secret/data/swarm/agents/<agent>/*, which covers this path and the bao-mtls one beside it alike -- which is also why this unit degrades where the identity check fails. A refusal this unit sees and that check did not cannot be a policy that drifted; it is an object not yet minted, the ordinary state of every agent created before its swarm knew to mint one. The harness resolves the path and reports which credential this agent can present. It does not yet present it: the auth-callout responder still verifies only the hive-scoped token, and an agent offering a credential nothing on the other end reads back would simply be refused. Teaching swarm-nats-auth to read the same path is the next slice.
This commit is contained in:
parent
10427467b3
commit
afdfce67ec
4 changed files with 416 additions and 2 deletions
|
|
@ -55,6 +55,7 @@ in
|
|||
./otel.nix
|
||||
./packages.nix
|
||||
./queue.nix
|
||||
./queue-identity.nix
|
||||
./renamed-options.nix
|
||||
./user.nix
|
||||
./screen.nix
|
||||
|
|
|
|||
Loading…
Reference in a new issue