hive-runtime: read the ACP provider key from bao
An opencode ACP agent got its provider API key only from the hand-placed backendEnvironmentFile. It now also reads it from the swarm secret store at swarm/agents/<agent>/acp-provider, field api_key, under its own certificate, and sets it in the spawned ACP agent's environment only. Nothing is written to disk. Precedence: a value already in the process environment (the env file) wins and the store is not asked. Otherwise the stored key is used when present. With no store, nothing stored, or a failed read, the agent is spawned without the key as before, and one line is logged without the value. The variable name comes from the existing per-agent option acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the harness only for the opencode preset. Other ACP commands are unchanged. The read lives in hive-runtime, where the ACP child is spawned, so both hive-agent and hive-subagent-daemon use it. The subagent daemon unit gets the key name and, when the agent has a store, the agent's store identity (the same credentials queue-identity.nix gives the harness). No new option or setting. Closes #4841.
This commit is contained in:
parent
c2bdf30e05
commit
c5b21403a6
13 changed files with 486 additions and 9 deletions
|
|
@ -30,6 +30,12 @@ let
|
|||
# has the memory to spare, which is what keeps overprovisioning
|
||||
# (several agents that rarely compile at the same time) working.
|
||||
subagentMemoryHigh = containerMemoryMaxBytes * 2 / 3;
|
||||
# Set on the harness only for an ACP agent on the opencode preset
|
||||
# (./agent-service.nix). The subagent daemon then reads that key from the
|
||||
# store as this agent, so it is handed the same store identity
|
||||
# ./queue-identity.nix hands the harness.
|
||||
acpApiKeyEnv = config.systemd.services.hive-agent.environment.HIVE_ACP_API_KEY_ENV or null;
|
||||
subagentReadsStore = acpApiKeyEnv != null && config.services.hyperhive.agent.bao.addr != null;
|
||||
in
|
||||
{
|
||||
options.services.hyperhive.agent.allowedRecipients = lib.mkOption {
|
||||
|
|
@ -392,12 +398,13 @@ in
|
|||
# — the same "absent" the harness itself would see.
|
||||
HIVE_TOOL_GROUPS = config.systemd.services.hive-agent.environment.HIVE_TOOL_GROUPS or null;
|
||||
# The harness's runtime selection, forwarded the same way, so an ACP
|
||||
# agent's subagents run on its ACP agent. All four are absent on a
|
||||
# agent's subagents run on its ACP agent. All five are absent on a
|
||||
# claude agent, which the daemon reads as claude.
|
||||
HIVE_RUNTIME = config.systemd.services.hive-agent.environment.HIVE_RUNTIME or null;
|
||||
HIVE_ACP_COMMAND = config.systemd.services.hive-agent.environment.HIVE_ACP_COMMAND or null;
|
||||
HIVE_ACP_ARGS = config.systemd.services.hive-agent.environment.HIVE_ACP_ARGS or null;
|
||||
HIVE_ACP_ENV = config.systemd.services.hive-agent.environment.HIVE_ACP_ENV or null;
|
||||
HIVE_ACP_API_KEY_ENV = acpApiKeyEnv;
|
||||
# Same `services.hyperhive.agent.availableModels` the harness's own assertions gate
|
||||
# the primary session's model against, so a subagent can't be spawned
|
||||
# on a model the operator didn't make available to this agent. The
|
||||
|
|
@ -424,6 +431,14 @@ in
|
|||
# only — the operator's ruling was explicit that the main agent's
|
||||
# environment stays as is.
|
||||
BASH_DEFAULT_TIMEOUT_MS = "1800000"; # 30 minutes
|
||||
}
|
||||
// lib.optionalAttrs subagentReadsStore {
|
||||
# Paths and a name only. `%d` is this unit's own credentials directory.
|
||||
HIVE_AGENT_NAME = userName;
|
||||
BAO_ADDR = config.services.hyperhive.agent.bao.addr;
|
||||
BAO_CLIENT_CERT = "%d/hive-agent-bao-cert";
|
||||
BAO_CLIENT_KEY = "%d/hive-agent-bao-key";
|
||||
BAO_CACERT = "%d/hive-agent-bao-server-ca";
|
||||
};
|
||||
serviceConfig = {
|
||||
ExecStart = "${config.services.hyperhive.agent.packages.hive-subagent-daemon}/bin/hive-subagent-daemon --http 127.0.0.1:${toString config.services.hyperhive.agent.mcp.subagentHttpPort}";
|
||||
|
|
@ -459,6 +474,15 @@ in
|
|||
// lib.optionalAttrs (containerMemoryMaxBytes != null) {
|
||||
MemoryHigh = toString subagentMemoryHigh;
|
||||
}
|
||||
// lib.optionalAttrs subagentReadsStore {
|
||||
# Bare ids: inherits the credentials the container manager passed in,
|
||||
# the same form ./queue-identity.nix uses.
|
||||
LoadCredential = [
|
||||
"hive-agent-bao-cert"
|
||||
"hive-agent-bao-key"
|
||||
"hive-agent-bao-server-ca"
|
||||
];
|
||||
}
|
||||
//
|
||||
lib.optionalAttrs
|
||||
(
|
||||
|
|
|
|||
Loading…
Reference in a new issue