hive-c0re: stop minting agent forge tokens
Delete ensure_user_for and mint_and_persist_agent_token, the user step of sync_agent (the per-rebuild re-mint, #4644) and of forge_after_first_spawn, and the hive-priv WriteAgentForgeToken request that wrote the token into the agent's state dir. hivectl forge create-user now refuses an agent and points at swarmctl agent mint-forge-token. mint_token, ensure_user_exists and TOKEN_SCOPES stay: provision_user_token and the core bootstrap still call them. Refs #3782
This commit is contained in:
parent
dd32a395f7
commit
b5d07d4df2
10 changed files with 59 additions and 126 deletions
|
|
@ -527,7 +527,7 @@ pub(crate) async fn resolve_approval_dag(
|
|||
let mut terminal_tag = None;
|
||||
match approval.kind {
|
||||
ApprovalKind::Spawn => {
|
||||
// Post-spawn forge bookkeeping (user, config repo mirror, meta
|
||||
// Post-spawn forge bookkeeping (config repo mirror, meta
|
||||
// access) — warn-only, then the resolution events + a rescan so
|
||||
// the dashboard reflects the post-spawn state either way.
|
||||
if result.is_ok() {
|
||||
|
|
@ -605,13 +605,10 @@ fn fetch_approval_for_worker(
|
|||
}
|
||||
|
||||
/// Forge bookkeeping run once after the very first container spawn:
|
||||
/// create the per-agent forge user, mirror the applied repo, and grant
|
||||
/// read access to core/meta. Also rescans containers so the dashboard
|
||||
/// reflects the post-spawn state.
|
||||
/// mirror the applied repo and grant read access to core/meta. The
|
||||
/// agent's forge user and token are swarm-controller's, not this
|
||||
/// hive's. Also rescans containers so the dashboard reflects the post-spawn state.
|
||||
async fn forge_after_first_spawn(coord: &Arc<Coordinator>, agent: &str) {
|
||||
if let Err(e) = crate::forge::ensure_user_for(agent).await {
|
||||
tracing::warn!(%agent, error = ?e, "forge: ensure_user after first spawn failed");
|
||||
}
|
||||
if let Err(e) = crate::forge::ensure_config_repo(agent).await {
|
||||
tracing::warn!(%agent, error = ?e, "forge: ensure_config_repo after first spawn failed");
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue