Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/swarm-controller/src
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 23e0c313b8 swarm-controller: sweep agents' legacy hyperhive-* forge tokens at start
Before b5d07d4d, hive-c0re minted a new `hyperhive-<unix-seconds>` token
for an agent on every spawn and rebuild and never revoked one, so every
live agent's forge user carries a pile of write-scoped tokens nothing
holds. Nothing in the tree lists or deletes them.

On each start, swarm-controller now walks the store's hive-agent-*
roster (the one the swarm-agent mint pass walks), and for every agent
whose swarm-agent token that pass would keep, deletes each token named
exactly `hyperhive-<digits>`. It logs the count per agent and a total.

- `core` is refused by name in both the roster filter and the per-user
  delete: hive-c0re still names core's live admin token
  `hyperhive-<unix-seconds>`.
- An agent whose swarm-agent token is not current is skipped, because
  consumers fall back to `<state>/forge-token`, the last hyperhive-*
  token, until the swarm token is fetched.
- A failed list or delete is logged and skipped; the sweep does not
  retry and never blocks startup. A second start deletes nothing.

Tokens on forge users of agents no longer on the store roster (already
destroyed) are not reached.

Closes #4644
2026-09-29 22:13:32 +02:00
..
forge swarm-controller: sweep agents' legacy hyperhive-* forge tokens at start 2026-09-29 22:13:32 +02:00
matrix_account swarm-controller: mint each agent's matrix account with the swarm's token 2026-09-25 08:31:01 +02:00
agent_icon.rs swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
agent_identity.rs swarm: tests and docs for the queue-credential revocation 2026-09-28 23:46:17 +02:00
agent_renewal.rs swarm-controller: backfill a missing queue-secret mint time instead of re-minting it 2026-09-28 22:24:07 +02:00
agent_state_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
agent_status.rs swarm-ui: add agent start/stop, backed by the wanted-state route 2026-09-02 19:57:04 +02:00
auth.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
config_pr.rs swarm-controller: fix stale route reference in snapshot's doc comment 2026-08-19 22:27:12 +02:00
forge.rs swarm-controller: sweep agents' legacy hyperhive-* forge tokens at start 2026-09-29 22:13:32 +02:00
issue_report.rs swarm-controller: answer 404, not 503, for an issue-report on a nonexistent repo 2026-09-24 16:38:47 +02:00
main.rs swarm-controller: sweep agents' legacy hyperhive-* forge tokens at start 2026-09-29 22:13:32 +02:00
matrix_account.rs Make agent creation swarm-only and refuse a name placed on another hive 2026-09-29 15:47:40 +02:00
otel_http_client.rs swarm-queue-client: request the bearer-authz scope when minting an agent token 2026-09-17 09:51:44 +02:00
queue_identity.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
read_policy.rs swarm: say the read policy names the hive it is written for 2026-09-12 11:41:01 +02:00
status.rs swarm-controller: make status::render/row pub(crate) so agent_status.rs's doc links resolve 2026-09-02 10:20:29 +02:00
store.rs fix doc-comment pointers broken by the module-eval split 2026-09-20 04:31:08 +02:00
term_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
vcs_metrics.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
wanted.rs swarm-controller: trim oversized comments, drop a trivial wrapper fn 2026-09-18 22:59:29 +02:00
webhook.rs swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00