agents: pull the forge token from bao; drop tea-login
forge-token.nix fetches swarm/agents/<agent>/forge-token under the agent's own store identity into /run/hive-agent-forge-token/token, and re-fetches on a timer so a rotation lands. hive-forge, the git credential helper, hive-forge-notify, forge-avatar-sync and the web UI read that file first and fall back to <state>/forge-token. tea-login is deleted: it copied the token into ~/.config/tea, which docs/swarm/credentials.md forbids for a store secret. hive-forge covers the same verbs. swarmctl gains agent mint-forge-token. Refs #3782
This commit is contained in:
parent
52c8c0b0de
commit
dd32a395f7
16 changed files with 501 additions and 156 deletions
|
|
@ -1,5 +1,6 @@
|
|||
//! App-level Forgejo client wrapper. Identity is the per-agent token
|
||||
//! under `${HYPERHIVE_STATE_DIR}/forge-token`. REST calls go through
|
||||
//! App-level Forgejo client wrapper. Identity is the per-agent token at
|
||||
//! `$HIVE_FORGE_TOKEN_FILE`, else `${HYPERHIVE_STATE_DIR}/forge-token`
|
||||
//! (see `read_token`). REST calls go through
|
||||
//! the typed [`forgejo_api::sync::Forgejo`] client (exposed via
|
||||
//! [`Client::api`]); a minimal raw `reqwest` client remains for the
|
||||
//! few *web-router* routes Forgejo does not serve under `/api/v1/`
|
||||
|
|
@ -462,9 +463,20 @@ fn state_dir() -> PathBuf {
|
|||
}
|
||||
}
|
||||
|
||||
/// Locate and read the forge token. Falls back to `$PWD/forge-token`
|
||||
/// when `HYPERHIVE_STATE_DIR` isn't set, matching the bash helper.
|
||||
/// Locate and read the forge token: `HIVE_FORGE_TOKEN_FILE` first (the
|
||||
/// copy the agent fetched from the swarm secret store, set by
|
||||
/// `nix/agent-modules/forge-token.nix`) when it names a non-empty file,
|
||||
/// otherwise `<state dir>/forge-token`, the file the hive used to write.
|
||||
/// The state dir falls back to `$PWD` when `HYPERHIVE_STATE_DIR` isn't
|
||||
/// set, matching the bash helper.
|
||||
fn read_token() -> Result<String> {
|
||||
if let Ok(fetched) = std::env::var("HIVE_FORGE_TOKEN_FILE")
|
||||
&& !fetched.is_empty()
|
||||
&& let Ok(raw) = std::fs::read_to_string(&fetched)
|
||||
&& !raw.trim().is_empty()
|
||||
{
|
||||
return Ok(raw.trim().to_owned());
|
||||
}
|
||||
let path = state_dir().join("forge-token");
|
||||
let raw = std::fs::read_to_string(&path)
|
||||
.with_context(|| format!("hive-forge: no forge-token at {}", path.display()))?;
|
||||
|
|
|
|||
Loading…
Reference in a new issue