hivectl: drop forge create-user; SSO makes a human's forge account

The forge now creates a human's account on their first authelia login,
so the verb has no job left. Deletes it, HostRequest::ForgeCreateUser,
its handler, provision_user_token, change_user_password and the hive's
TOKEN_SCOPES. change_user_password also passed the password as an
argument to `forgejo admin user change-password`, so it showed in the
container's process list.

ensure_user_exists and mint_token stay for the `core` bootstrap, their
one caller now. ensure_user_exists loses its password parameter: only the
deleted path set one.

Refs #3782
This commit is contained in:
atlas 2026-09-24 23:59:13 +02:00 • committed by mara
commit ef494af188
10 changed files with 40 additions and 227 deletions

View file

@ -11,7 +11,7 @@ use std::path::PathBuf;
long_about = "\
Sibling to the `hive-c0re` daemon binary. Covers host-side admin \
operations that don't go through the broker — manual user \
provisioning on the bundled forge + matrix containers, plus future \
provisioning on the bundled matrix container, plus future \
recovery / debugging verbs.\
"
)]
@ -28,11 +28,10 @@ pub struct Cli {
#[derive(Subcommand)]
pub enum Cmd {
/// Forgejo user provisioning.
/// Reconcile an agent's config between this hive and the forge.
///
/// Manual entry point to the same idempotent provisioning c0re runs at
/// boot — for recovery, ad-hoc reprovisioning, or fixing one agent
/// without bouncing the daemon.
/// A human's first SSO login to the forge makes their forge
/// account.
Forge {
#[command(subcommand)]
cmd: ForgeCmd,
@ -248,30 +247,6 @@ impl ScopeArgs {
#[derive(Subcommand)]
pub enum ForgeCmd {
/// Create or refresh a non-agent Forgejo account + token for `<name>`.
///
/// Prints the token to stdout. Set a password to enable forge web-UI
/// login (otherwise it uses a random throwaway). Refused for an
/// existing agent: swarm-controller mints an agent's token
/// (`swarmctl agent mint-forge-token <agent>`).
CreateUser {
/// Forgejo username of a human/other account — `mara`,
/// `damocles`, etc.
name: String,
/// Set the account password to this string instead of a random
/// throwaway. Use this for operator accounts that need to log
/// into the forge web UI. Mutually exclusive with
/// `--password-stdin`. WARNING: the password is visible in
/// shell history + process listings; prefer `--password-stdin`
/// for anything sensitive.
#[arg(long)]
password: Option<String>,
/// Read the password from stdin (single line, trailing newline
/// stripped) instead of an inline flag. Mutually exclusive with
/// `--password`.
#[arg(long, conflicts_with = "password")]
password_stdin: bool,
},
/// Show + reconcile the divergence between an agent's local applied
/// config checkout and its forge `agent-configs/<agent>` main.
///

View file

@ -1,6 +1,5 @@
//! `hivectl forge create-user <name>` — provision a Forgejo account via the
//! daemon (which owns the forge admin token);
//! hivectl just resolves the password client-side and relays the request.
//! `hivectl forge reconcile-config <agent>` — show and reconcile an
//! agent's config divergence via the daemon.
use std::io::{self, Write};
use std::path::Path;
@ -9,29 +8,7 @@ use anyhow::Result;
use hive_host_sock::{HostRequest, ReconcileDirection};
use crate::cli::ReconcileFrom;
use crate::util::{daemon_request, resolve_password};
pub(crate) async fn forge_create_user(
socket: &Path,
name: &str,
password: Option<&str>,
password_stdin: bool,
) -> Result<()> {
// Resolve the password client-side (inline flag or stdin read); the
// daemon never touches this process's stdin. The is-present check, the
// agent-vs-operator branch, and token persistence now live in the
// daemon handler.
let password = resolve_password(password, password_stdin)?;
daemon_request(
socket,
hive_host_sock::HostRequest::ForgeCreateUser {
name: crate::util::parse_ident(name)?,
password,
},
"forge",
)
.await
}
use crate::util::daemon_request;
/// `hivectl forge reconcile-config <agent> [--from <forge|local>] [--verbose]`.
/// Always shows the divergence first (daemon computes it read-only), then

View file

@ -45,7 +45,7 @@ mod github;
mod watch;
use github::github_set_token;
mod forge;
use forge::{forge_create_user, forge_reconcile_config};
use forge::forge_reconcile_config;
mod agents;
use agents::{agents_list, run_agent};
mod power;
@ -66,11 +66,6 @@ async fn main() -> Result<()> {
let socket = cli.socket;
match cli.cmd {
Cmd::Forge { cmd } => match cmd {
ForgeCmd::CreateUser {
name,
password,
password_stdin,
} => forge_create_user(&socket, &name, password.as_deref(), password_stdin).await,
ForgeCmd::ReconcileConfig {
agent,
from,