Watch
0
0
Fork
You've already forked hyperhive
0

hive-c0re: stop minting agent forge tokens

Delete ensure_user_for and mint_and_persist_agent_token, the user step
of sync_agent (the per-rebuild re-mint, #4644) and of
forge_after_first_spawn, and the hive-priv WriteAgentForgeToken request
that wrote the token into the agent's state dir. hivectl forge
create-user now refuses an agent and points at swarmctl agent
mint-forge-token. mint_token, ensure_user_exists and TOKEN_SCOPES stay:
provision_user_token and the core bootstrap still call them.

Refs #3782
This commit is contained in:
atlas 2026-09-24 16:39:45 +02:00 • committed by mara
commit b5d07d4df2
10 changed files with 59 additions and 126 deletions

View file

@ -403,11 +403,6 @@ async fn exec(
paused,
} => exec_set_agent_paused(agent_name, paused),
PrivRequest::WriteAgentForgeToken {
ref agent_name,
ref token,
} => write_forge_token(agent_name, token),
PrivRequest::WriteAgentMatrixToken {
ref agent_name,
ref token,
@ -619,12 +614,6 @@ fn exec_set_agent_paused(agent_name: &str, paused: bool) -> Result<(String, Stri
set_agent_paused(agent_name, paused)
}
/// `WriteAgentForgeToken`.
fn write_forge_token(agent_name: &str, token: &str) -> Result<(String, String)> {
validate_agent_name(agent_name)?;
write_agent_state_file(agent_name, "forge-token", &format!("{token}\n"))
}
/// `WriteAgentGithubToken`.
fn write_github_token(agent_name: &str, token: &str) -> Result<(String, String)> {
validate_agent_name(agent_name)?;
@ -1441,7 +1430,7 @@ struct ForgeSidecar<'a> {
base_url: &'a str,
}
/// Shared helper for `WriteAgentForgeToken` and `WriteAgentMatrixToken`.
/// Shared helper for the `WriteAgent*Token` requests.
/// Writes `content` to `AGENT_STATE_ROOT/<agent_name>/state/<filename>`,
/// chowns to the agent user (derived from the state dir's existing owner),
/// and chmods 0600. Running as root (hive-priv), so this succeeds