Watch
0
0
Fork
You've already forked hyperhive
0

hive-runtime: read the ACP provider key from bao

An opencode ACP agent got its provider API key only from the hand-placed
backendEnvironmentFile. It now also reads it from the swarm secret store
at swarm/agents/<agent>/acp-provider, field api_key, under its own
certificate, and sets it in the spawned ACP agent's environment only.
Nothing is written to disk.

Precedence: a value already in the process environment (the env file)
wins and the store is not asked. Otherwise the stored key is used when
present. With no store, nothing stored, or a failed read, the agent is
spawned without the key as before, and one line is logged without the
value.

The variable name comes from the existing per-agent option
acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the
harness only for the opencode preset. Other ACP commands are unchanged.

The read lives in hive-runtime, where the ACP child is spawned, so both
hive-agent and hive-subagent-daemon use it. The subagent daemon unit
gets the key name and, when the agent has a store, the agent's store
identity (the same credentials queue-identity.nix gives the harness).

No new option or setting. Closes #4841.
This commit is contained in:
atlas 2026-09-30 21:23:05 +02:00 • committed by mara
commit c5b21403a6
13 changed files with 486 additions and 9 deletions

View file

@ -0,0 +1,64 @@
//! The ACP provider agreement: where an agent's inference-provider API key
//! lives in the store, and what the object at that path holds.
//!
//! The operator writes it by hand; the agent reads it under its own
//! certificate when it spawns its ACP agent (`hive_runtime`).
use serde::{Deserialize, Serialize};
use crate::{
Error,
path::{Kind, principal_prefix},
};
/// The path holding `agent`'s ACP provider API key.
///
/// A flat leaf under the agent's prefix, like [`crate::forge::agent_token_path`],
/// so the agent's own read stanza ([`crate::policy::render_agent`]) already
/// covers it.
///
/// # Errors
/// [`Error::PathSegment`] when `agent` contains anything but `[A-Za-z0-9_-]`,
/// which is what keeps one agent's name from addressing another agent's secret.
pub fn provider_key_path(agent: &str) -> Result<String, Error> {
let prefix = principal_prefix(Kind::Agent, agent)?;
Ok(format!("{prefix}/acp-provider"))
}
/// What an agent's ACP provider path holds.
///
/// No `Debug`: `api_key` is a live provider credential.
#[derive(Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ProviderKey {
/// The key itself. The operator enters this field name in the store's UI.
pub api_key: String,
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn the_key_lands_under_the_agent_prefix() {
// Spelled out: the operator types this path into the store's UI.
assert_eq!(
provider_key_path("atlas").expect("a plain name is legal"),
"swarm/agents/atlas/acp-provider"
);
}
#[test]
fn a_traversal_in_the_agent_name_is_refused() {
for bad in ["../argus", "a/b", "a.b", ""] {
let e = provider_key_path(bad).expect_err("a traversal is not legal");
assert!(matches!(e, Error::PathSegment { kind: "agent", .. }), "{e}");
}
}
#[test]
fn the_stored_field_is_api_key() {
let stored: ProviderKey =
serde_json::from_str(r#"{"api_key":"k"}"#).expect("the documented shape decodes");
assert_eq!(stored.api_key, "k");
}
}

View file

@ -5,7 +5,7 @@
//! the rules every path obeys ([`path`]), the translation from this
//! deployment's environment into a logged-in client ([`client`]), and, per kind
//! of secret, the path it lives at together with the fields it holds
//! ([`matrix`], [`queue`], [`mtls`], [`forge`]). Each of those is a thing the controller
//! ([`matrix`], [`queue`], [`mtls`], [`forge`], [`acp`]). Each of those is a thing the controller
//! and a hive must say identically, so it is said once here.
//!
//! [`policy`] is the same kind of agreement seen from the other side: which of
@ -22,6 +22,7 @@
//! [`mtls`] is the one module about reaching the store rather than about a
//! value inside it, and its doc explains why that is not circular.
pub mod acp;
pub mod client;
pub mod forge;
pub mod matrix;