agents: pull the forge token from bao; drop tea-login
forge-token.nix fetches swarm/agents/<agent>/forge-token under the agent's own store identity into /run/hive-agent-forge-token/token, and re-fetches on a timer so a rotation lands. hive-forge, the git credential helper, hive-forge-notify, forge-avatar-sync and the web UI read that file first and fall back to <state>/forge-token. tea-login is deleted: it copied the token into ~/.config/tea, which docs/swarm/credentials.md forbids for a store secret. hive-forge covers the same verbs. swarmctl gains agent mint-forge-token. Refs #3782
This commit is contained in:
parent
52c8c0b0de
commit
dd32a395f7
16 changed files with 501 additions and 156 deletions
|
|
@ -351,7 +351,12 @@ fn agent_links(label: &str, gui_enabled: bool) -> Vec<AgentLink> {
|
|||
});
|
||||
}
|
||||
|
||||
if crate::paths::state_dir().join("forge-token").is_file() {
|
||||
// Either copy of the forge token: the one fetched from the swarm secret
|
||||
// store (`HIVE_FORGE_TOKEN_FILE`), or the state-dir file the hive used
|
||||
// to write.
|
||||
let fetched_token = std::env::var_os("HIVE_FORGE_TOKEN_FILE")
|
||||
.is_some_and(|p| std::path::Path::new(&p).is_file());
|
||||
if fetched_token || crate::paths::state_dir().join("forge-token").is_file() {
|
||||
links.push(AgentLink {
|
||||
url: format!("/{label}"),
|
||||
icon: "🔨".to_owned(),
|
||||
|
|
|
|||
Loading…
Reference in a new issue