hive-c0re: stop minting agent forge tokens
Delete ensure_user_for and mint_and_persist_agent_token, the user step of sync_agent (the per-rebuild re-mint, #4644) and of forge_after_first_spawn, and the hive-priv WriteAgentForgeToken request that wrote the token into the agent's state dir. hivectl forge create-user now refuses an agent and points at swarmctl agent mint-forge-token. mint_token, ensure_user_exists and TOKEN_SCOPES stay: provision_user_token and the core bootstrap still call them. Refs #3782
This commit is contained in:
parent
dd32a395f7
commit
b5d07d4df2
10 changed files with 59 additions and 126 deletions
|
|
@ -361,18 +361,6 @@ pub async fn set_agent_paused(agent_name: &str, paused: bool) -> Result<()> {
|
|||
.await?)
|
||||
}
|
||||
|
||||
/// Write the Forgejo access token for `agent_name` to
|
||||
/// `<agent_state_root>/<agent_name>/state/forge-token` via hive-priv
|
||||
/// (running as root). The file is written 0600 and chowned to the agent
|
||||
/// user so it is readable from inside the agent container.
|
||||
pub async fn write_agent_forge_token(agent_name: &str, token: &str) -> Result<()> {
|
||||
ok(call(&PrivRequest::WriteAgentForgeToken {
|
||||
agent_name: agent_name.to_owned(),
|
||||
token: token.to_owned(),
|
||||
})
|
||||
.await?)
|
||||
}
|
||||
|
||||
/// Write a Matrix access token for `agent_name` via hive-priv (running as
|
||||
/// root). `account: None` writes the hive-internal
|
||||
/// `<state>/matrix-token`; `account: Some(name)` writes
|
||||
|
|
|
|||
Loading…
Reference in a new issue