hyperhive/swarm-authelia-bridge-sock
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 3700167279 feat(swarm-authelia-bridge): mark agent identities with a group, and answer for the set
The users database holds humans and agents in one namespace and nothing in
it said which was which, so a roster read had no predicate to read with.

Marks positively, at creation. The alternative — everyone who is not an
operator — fails in the direction that matters: an account created without
a group is an operator who cannot log in, a mistake the swarm UI docs
already warn about, and it would have rendered as an agent. The group is a
constant for the same reason the operator group it mirrors is one.

An identity that predates the marker gains it when agent creation runs
again, which is already the agreed migration for those; AlreadyExists
therefore reports that the subject was there, not that nothing was written.

ListAgentIdentities reads through this process because the store is owned
by a uid swarm-controller does not have — the same reason the write goes
through here — and answers with names alone, never the digests it sits next
to.
2026-08-20 00:15:48 +02:00
..
src feat(swarm-authelia-bridge): mark agent identities with a group, and answer for the set 2026-08-20 00:15:48 +02:00
Cargo.toml add swarm-authelia-bridge: the only thing allowed to write swarm-authelia's users database 2026-08-16 22:38:40 +02:00
README.md feat(swarm-authelia-bridge): mark agent identities with a group, and answer for the set 2026-08-20 00:15:48 +02:00

swarm-authelia-bridge-sock

Wire types for the swarm-authelia-bridge socket — the contract between swarm-authelia-bridge (server, runs alongside swarm-authelia) and swarm-controller (client).

Why it's its own crate

Same rationale as hive-priv-sock (which this mirrors in spirit, though the transport differs — this bridge is network-facing HTTP, not a unix socket, since it has to reach a possibly-split-host swarm-controller): the bridge is a narrowly-scoped, unprivileged-but-file-owning helper, and splitting the wire contract out of any larger crate keeps both its own dependency footprint and its interface small enough to audit at a glance. No server or client logic here, only the request/response shapes both sides import.

Shape

Two operations: idempotently ensure an agent exists as an authelia subject, and list the ones that do. Deliberately not a wholesale-replace-the-file API — the bridge reads users.yml, changes what the request named, and writes it back; a caller only ever asks for one user to exist, never sends rendered YAML or a file blob. See swarm-authelia-bridge/README.md for the helper itself.