hivectl: drop forge create-user; SSO makes a human's forge account
The forge now creates a human's account on their first authelia login, so the verb has no job left. Deletes it, HostRequest::ForgeCreateUser, its handler, provision_user_token, change_user_password and the hive's TOKEN_SCOPES. change_user_password also passed the password as an argument to `forgejo admin user change-password`, so it showed in the container's process list. ensure_user_exists and mint_token stay for the `core` bootstrap, their one caller now. ensure_user_exists loses its password parameter: only the deleted path set one. Refs #3782
This commit is contained in:
parent
113f3fe6e2
commit
ef494af188
10 changed files with 40 additions and 227 deletions
|
|
@ -6,7 +6,6 @@ This document contains the help content for the `hivectl` command-line program.
|
|||
|
||||
* [`hivectl`↴](#hivectl)
|
||||
* [`hivectl forge`↴](#hivectl-forge)
|
||||
* [`hivectl forge create-user`↴](#hivectl-forge-create-user)
|
||||
* [`hivectl forge reconcile-config`↴](#hivectl-forge-reconcile-config)
|
||||
* [`hivectl matrix`↴](#hivectl-matrix)
|
||||
* [`hivectl matrix create-user`↴](#hivectl-matrix-create-user)
|
||||
|
|
@ -63,13 +62,13 @@ This document contains the help content for the `hivectl` command-line program.
|
|||
|
||||
## `hivectl`
|
||||
|
||||
Sibling to the `hive-c0re` daemon binary. Covers host-side admin operations that don't go through the broker — manual user provisioning on the bundled forge + matrix containers, plus future recovery / debugging verbs.
|
||||
Sibling to the `hive-c0re` daemon binary. Covers host-side admin operations that don't go through the broker — manual user provisioning on the bundled matrix container, plus future recovery / debugging verbs.
|
||||
|
||||
**Usage:** `hivectl [OPTIONS] <COMMAND>`
|
||||
|
||||
###### **Subcommands:**
|
||||
|
||||
* `forge` — Forgejo user provisioning
|
||||
* `forge` — Reconcile an agent's config between this hive and the forge
|
||||
* `matrix` — matrix-tuwunel user provisioning
|
||||
* `github` — GitHub account provisioning
|
||||
* `gateway` — Gateway htpasswd user management
|
||||
|
|
@ -95,38 +94,18 @@ Sibling to the `hive-c0re` daemon binary. Covers host-side admin operations that
|
|||
|
||||
## `hivectl forge`
|
||||
|
||||
Forgejo user provisioning.
|
||||
Reconcile an agent's config between this hive and the forge.
|
||||
|
||||
Manual entry point to the same idempotent provisioning c0re runs at boot — for recovery, ad-hoc reprovisioning, or fixing one agent without bouncing the daemon.
|
||||
A human's first SSO login to the forge makes their forge account.
|
||||
|
||||
**Usage:** `hivectl forge <COMMAND>`
|
||||
|
||||
###### **Subcommands:**
|
||||
|
||||
* `create-user` — Create or refresh a non-agent Forgejo account + token for `<name>`
|
||||
* `reconcile-config` — Show + reconcile the divergence between an agent's local applied config checkout and its forge `agent-configs/<agent>` main
|
||||
|
||||
|
||||
|
||||
## `hivectl forge create-user`
|
||||
|
||||
Create or refresh a non-agent Forgejo account + token for `<name>`.
|
||||
|
||||
Prints the token to stdout. Set a password to enable forge web-UI login (otherwise it uses a random throwaway). Refused for an existing agent: swarm-controller mints an agent's token (`swarmctl agent mint-forge-token <agent>`).
|
||||
|
||||
**Usage:** `hivectl forge create-user [OPTIONS] <NAME>`
|
||||
|
||||
###### **Arguments:**
|
||||
|
||||
* `<NAME>` — Forgejo username of a human/other account — `mara`, `damocles`, etc
|
||||
|
||||
###### **Options:**
|
||||
|
||||
* `--password <PASSWORD>` — Set the account password to this string instead of a random throwaway. Use this for operator accounts that need to log into the forge web UI. Mutually exclusive with `--password-stdin`. WARNING: the password is visible in shell history + process listings; prefer `--password-stdin` for anything sensitive
|
||||
* `--password-stdin` — Read the password from stdin (single line, trailing newline stripped) instead of an inline flag. Mutually exclusive with `--password`
|
||||
|
||||
|
||||
|
||||
## `hivectl forge reconcile-config`
|
||||
|
||||
Show + reconcile the divergence between an agent's local applied config checkout and its forge `agent-configs/<agent>` main.
|
||||
|
|
|
|||
Loading…
Reference in a new issue