hive-c0re: stop minting agent forge tokens
Delete ensure_user_for and mint_and_persist_agent_token, the user step of sync_agent (the per-rebuild re-mint, #4644) and of forge_after_first_spawn, and the hive-priv WriteAgentForgeToken request that wrote the token into the agent's state dir. hivectl forge create-user now refuses an agent and points at swarmctl agent mint-forge-token. mint_token, ensure_user_exists and TOKEN_SCOPES stay: provision_user_token and the core bootstrap still call them. Refs #3782
This commit is contained in:
parent
dd32a395f7
commit
b5d07d4df2
10 changed files with 59 additions and 126 deletions
|
|
@ -468,19 +468,6 @@ pub enum PrivRequest {
|
|||
},
|
||||
|
||||
// --- Agent credential writes ---
|
||||
/// Write `forge-token` into `AGENT_STATE_ROOT/<agent_name>/state/forge-token`.
|
||||
///
|
||||
/// hive-priv validates `agent_name`, creates the state dir if absent,
|
||||
/// writes the file 0600, and chowns it to the state dir's owner so
|
||||
/// the agent process can read it. Required because hive-c0re runs
|
||||
/// unprivileged and cannot write to agent-owned state directories.
|
||||
WriteAgentForgeToken {
|
||||
/// Logical agent name (validated by `validate_agent_name`).
|
||||
agent_name: String,
|
||||
/// Token value. hive-priv appends a trailing newline before writing.
|
||||
token: String,
|
||||
},
|
||||
|
||||
/// Write a matrix access token into the agent's state dir. With
|
||||
/// `account: None` it targets the hive-internal `matrix-token`; with
|
||||
/// `account: Some(name)` it targets `matrix-token-<name>` for an extra
|
||||
|
|
@ -488,8 +475,10 @@ pub enum PrivRequest {
|
|||
/// `account` suffix as plain identifiers before building the path, so a
|
||||
/// crafted account name cannot traverse out of the state dir.
|
||||
///
|
||||
/// Same write semantics as `WriteAgentForgeToken` — validates names,
|
||||
/// creates dir, writes 0600, chowns to agent owner.
|
||||
/// hive-priv validates the names, creates the state dir if absent,
|
||||
/// writes the file 0600, and chowns it to the state dir's owner so the
|
||||
/// agent process can read it. Required because hive-c0re runs
|
||||
/// unprivileged and cannot write to agent-owned state directories.
|
||||
WriteAgentMatrixToken {
|
||||
/// Logical agent name (validated by `validate_agent_name`).
|
||||
agent_name: String,
|
||||
|
|
@ -512,7 +501,7 @@ pub enum PrivRequest {
|
|||
/// The operator-supplied GitHub personal access token (PAT) for the
|
||||
/// agent's GitHub integration (`services.hyperhive.agent.github.enable`). Same write
|
||||
/// semantics as
|
||||
/// `WriteAgentForgeToken` — validates `agent_name`, creates the state dir
|
||||
/// `WriteAgentMatrixToken` — validates `agent_name`, creates the state dir
|
||||
/// if absent, writes the file 0600, and chowns it to the agent so the
|
||||
/// `gh` wrapper / git credential helper can read it. No account suffix
|
||||
/// (single GitHub account per agent).
|
||||
|
|
@ -534,7 +523,7 @@ pub enum PrivRequest {
|
|||
/// `label` MUST be validated as a plain identifier (same rule as the
|
||||
/// matrix `account` suffix) before it goes into the filename — a
|
||||
/// crafted label could otherwise traverse out of the state dir. Same
|
||||
/// write semantics as `WriteAgentForgeToken` — validates `agent_name`,
|
||||
/// write semantics as `WriteAgentMatrixToken` — validates `agent_name`,
|
||||
/// creates the state dir if absent, writes both files 0600, chowns to
|
||||
/// the agent.
|
||||
WriteAgentExtraForgeAccount {
|
||||
|
|
|
|||
Loading…
Reference in a new issue