hive-c0re: stop minting agent forge tokens
Delete ensure_user_for and mint_and_persist_agent_token, the user step of sync_agent (the per-rebuild re-mint, #4644) and of forge_after_first_spawn, and the hive-priv WriteAgentForgeToken request that wrote the token into the agent's state dir. hivectl forge create-user now refuses an agent and points at swarmctl agent mint-forge-token. mint_token, ensure_user_exists and TOKEN_SCOPES stay: provision_user_token and the core bootstrap still call them. Refs #3782
This commit is contained in:
parent
dd32a395f7
commit
b5d07d4df2
10 changed files with 59 additions and 126 deletions
|
|
@ -248,15 +248,15 @@ impl ScopeArgs {
|
|||
|
||||
#[derive(Subcommand)]
|
||||
pub enum ForgeCmd {
|
||||
/// Create or refresh the Forgejo account + token for `<name>`.
|
||||
/// Create or refresh a non-agent Forgejo account + token for `<name>`.
|
||||
///
|
||||
/// For an existing agent, persists the token to its state dir; for a
|
||||
/// human/other account, prints the token to stdout. Set a password to
|
||||
/// enable forge web-UI login (otherwise it uses a random throwaway).
|
||||
/// Prints the token to stdout. Set a password to enable forge web-UI
|
||||
/// login (otherwise it uses a random throwaway). Refused for an
|
||||
/// existing agent: swarm-controller mints an agent's token
|
||||
/// (`swarmctl agent mint-forge-token <agent>`).
|
||||
CreateUser {
|
||||
/// Forgejo username. For agents: the container/agent name
|
||||
/// (`<n>` in `h-<n>`; manager uses the literal `manager`).
|
||||
/// For humans: any forgejo username — `mara`, `damocles`, etc.
|
||||
/// Forgejo username of a human/other account — `mara`,
|
||||
/// `damocles`, etc.
|
||||
name: String,
|
||||
/// Set the account password to this string instead of a random
|
||||
/// throwaway. Use this for operator accounts that need to log
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
//! `hivectl forge create-user <name>` — provision a Forgejo account via the
|
||||
//! daemon (which owns the forge admin token + account-token persistence);
|
||||
//! daemon (which owns the forge admin token);
|
||||
//! hivectl just resolves the password client-side and relays the request.
|
||||
|
||||
use std::io::{self, Write};
|
||||
|
|
|
|||
Loading…
Reference in a new issue