agents: pull the forge token from bao; drop tea-login
forge-token.nix fetches swarm/agents/<agent>/forge-token under the agent's own store identity into /run/hive-agent-forge-token/token, and re-fetches on a timer so a rotation lands. hive-forge, the git credential helper, hive-forge-notify, forge-avatar-sync and the web UI read that file first and fall back to <state>/forge-token. tea-login is deleted: it copied the token into ~/.config/tea, which docs/swarm/credentials.md forbids for a store secret. hive-forge covers the same verbs. swarmctl gains agent mint-forge-token. Refs #3782
This commit is contained in:
parent
52c8c0b0de
commit
dd32a395f7
16 changed files with 501 additions and 156 deletions
|
|
@ -137,11 +137,9 @@ services.hyperhive.agent.forge.url = "http://forge.example:3000"; # default: nu
|
|||
services.hyperhive.agent.matrix.url = "https://matrix.example"; # default: null
|
||||
```
|
||||
|
||||
**`services.hyperhive.agent.forge.url`** — base URL of the Forgejo instance. Used by
|
||||
a one-shot boot unit (`tea-login`) that writes `~/.config/tea/config.yml`
|
||||
directly from the agent's `forge-token`, so `tea` and `hive-forge`
|
||||
work without an interactive auth step. The unit is a no-op when
|
||||
`forge-token` is absent. Override when the agent should connect to a
|
||||
**`services.hyperhive.agent.forge.url`** — base URL of the Forgejo instance. It scopes
|
||||
the git credential helper to this forge and is where `forge-avatar-sync`
|
||||
uploads the agent's icon. Override when the agent should connect to a
|
||||
Forgejo on a different host or port (for example a swarm peer's forge).
|
||||
Validated: must be an `http://` or `https://` URL, or `null`.
|
||||
|
||||
|
|
@ -149,7 +147,7 @@ Validated: must be an `http://` or `https://` URL, or `null`.
|
|||
loopback default would only ever be correct when the forge shares the
|
||||
agent's network namespace, and inside a container `localhost` is the
|
||||
agent itself, so the default was a value that built fine and then talked
|
||||
to the wrong machine. With `null` the `tea-login` and `forge-avatar-sync`
|
||||
to the wrong machine. With `null` the credential helper and `forge-avatar-sync`
|
||||
units aren't generated at all: an absent integration rather than a
|
||||
misdirected one. You don't normally set this — hive-c0re renders the
|
||||
host's real forge URL into every agent, and refuses to write a meta
|
||||
|
|
|
|||
Loading…
Reference in a new issue