docs: clear write-good.Passive hits in docs/swarm/sso.md

6 genuine passive-voice rewrites (actor named — the operator,
secrets.md, swarm-authelia.nix, the person who introduced the split,
swarmctl); 1 false positive left untouched — a quoted phrase +
predicate adjective ('presenting as "the forge is broken"').
This commit is contained in:
iris 2026-09-20 05:20:57 +02:00 committed by mara
commit c75604aa42

View file

@ -1,9 +1,9 @@
# Swarm SSO # Swarm SSO
The swarm runs one authelia, and it's two things at once: the **session The swarm runs one authelia, and it's two things at once: the **session
provider** every protected vhost checks (`auth_request`), and — once any provider** every protected vhost checks (`auth_request`), and — once an
client is declared — an **OIDC provider** issuing tokens to relying operator declares any client — an **OIDC provider** issuing tokens to
parties: the forge and the matrix homeserver. relying parties: the forge and the matrix homeserver.
The second role derives rather than switches: The second role derives rather than switches:
`services.hyperhive.swarm.authelia.oidc.clients` being non-empty turns it `services.hyperhive.swarm.authelia.oidc.clients` being non-empty turns it
@ -28,7 +28,7 @@ error reading the authentication database: could not validate the schema:
users: non zero value required users: non zero value required
``` ```
It then exits 1 and systemd restarts it, so a swarm that has been It then exits 1 and systemd restarts it, so a swarm the operator has
enabled but not bootstrapped shows a **crash-looping unit** and `502 Bad enabled but not bootstrapped shows a **crash-looping unit** and `502 Bad
Gateway` from the vhost — not a login page with nobody able to use it. Gateway` from the vhost — not a login page with nobody able to use it.
The gateway is working in that state; the upstream isn't up. The gateway is working in that state; the upstream isn't up.
@ -95,8 +95,8 @@ an attribute edit can invalidate a login by accident.
## What secrets exist, and where each one lives ## What secrets exist, and where each one lives
Every secret in the swarm, with its generator and its path, is tabulated [`secrets.md`](secrets.md) tabulates every secret in the swarm, with its
in one place: [`secrets.md`](secrets.md), including authelia's own keys generator and its path, in one place — including authelia's own keys
(session, JWT, storage-encryption, OIDC HMAC, OIDC issuer) and the two (session, JWT, storage-encryption, OIDC HMAC, OIDC issuer) and the two
halves of each client secret. That page's two rules — a secret is always halves of each client secret. That page's two rules — a secret is always
a path, never a value, and the generator and the reader typically live in a path, never a value, and the generator and the reader typically live in
@ -115,9 +115,11 @@ authelia's first boot to mint that client's secret and copies it into the
service's container, and the service's own module contributes its client service's container, and the service's own module contributes its client
entry — callback URL included — to authelia's client list. entry — callback URL included — to authelia's client list.
The callback is built once and read twice, so the redirect URI authelia Each relying service's own glue module builds its callback once, and
accepts and the one the service actually sends can't drift apart. A both authelia's client list and the service's own OIDC client config
mismatch there is a rejected login with no error text worth reading. read that same value, so the redirect URI authelia accepts and the one
the service actually sends can't drift apart. A mismatch there is a
rejected login with no error text worth reading.
⚠️ The delivery is a copy, not a `bindMounts` entry, and deliberately so: ⚠️ The delivery is a copy, not a `bindMounts` entry, and deliberately so:
nixos-container refuses to start a container whose bind source is nixos-container refuses to start a container whose bind source is
@ -238,7 +240,7 @@ upstream and compare three requests, not one:
All three matter. A change that silently deleted the browser page would All three matter. A change that silently deleted the browser page would
pass a deny-only check, and one that quietly stopped denying would pass a pass a deny-only check, and one that quietly stopped denying would pass a
page-only check. This was verified that way when the split was introduced. page-only check. The person who introduced the split verified it this way.
## What this doesn't do ## What this doesn't do
@ -254,6 +256,6 @@ page-only check. This was verified that way when the split was introduced.
door, and a dead provider locks everyone out, the built-in admin door, and a dead provider locks everyone out, the built-in admin
included. That's why `swarm.grafana.oidc.role` defaults to `Admin`; see included. That's why `swarm.grafana.oidc.role` defaults to `Admin`; see
[`services.md`](services.md#metrics-victoriametrics--grafana). [`services.md`](services.md#metrics-victoriametrics--grafana).
- **It doesn't provision users.** Agents are created and destroyed - **It doesn't provision users.** `swarmctl` creates and destroys agents
continuously, so the subject set belongs to a program rather than to a continuously today, so the subject set belongs to a program rather
config file; today that program is `swarmctl`. than to a config file.