agents: pull the forge token from bao; drop tea-login
forge-token.nix fetches swarm/agents/<agent>/forge-token under the agent's own store identity into /run/hive-agent-forge-token/token, and re-fetches on a timer so a rotation lands. hive-forge, the git credential helper, hive-forge-notify, forge-avatar-sync and the web UI read that file first and fall back to <state>/forge-token. tea-login is deleted: it copied the token into ~/.config/tea, which docs/swarm/credentials.md forbids for a store secret. hive-forge covers the same verbs. swarmctl gains agent mint-forge-token. Refs #3782
This commit is contained in:
parent
52c8c0b0de
commit
dd32a395f7
16 changed files with 501 additions and 156 deletions
|
|
@ -45,7 +45,7 @@
|
|||
# `/etc/hyperhive-bridge-dns` (containing the gateway IP) since
|
||||
# isolation is always on; the oneshot reads it and rewrites
|
||||
# resolv.conf on every boot. Ordered before the first DNS consumer
|
||||
# (tea-login) and the network targets so name resolution works for
|
||||
# (the forge-token fetch) and the network targets so name resolution works for
|
||||
# the very first turn.
|
||||
systemd.services.hyperhive-isolated-dns = {
|
||||
description = "point resolv.conf at the hive bridge resolver (isolated containers)";
|
||||
|
|
@ -61,7 +61,7 @@
|
|||
# is a harmless no-op when matrix is disabled (the unit is absent).
|
||||
before = [
|
||||
"network-online.target"
|
||||
"tea-login.service"
|
||||
"hive-agent-forge-token.service"
|
||||
"hive-agent.service"
|
||||
"hive-matrix-daemon.service"
|
||||
];
|
||||
|
|
|
|||
Loading…
Reference in a new issue