Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/swarmctl/src
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 5785c0024c Make agent creation swarm-only and refuse a name placed on another hive
swarm-controller's POST /api/agents now refuses (409) a name the swarm
has already placed on a different hive: a non-Destroyed declaration in
that hive's wanted state, or a SetAgentWanted node still queued for it.
The same name on the same hive is that agent being re-created and goes
through. A wanted state that cannot be read refuses (503/500) instead of
reading as "placed nowhere". Creations are serialised from that read to
the graph insert so two concurrent creations of one name cannot both
pass.

Hive-level creation is removed: hivectl `agent create` / `request-create`,
HostRequest::Spawn / RequestSpawn, the dashboard POST /api/request-spawn
route, and ApprovalKind::Spawn with its approve/resolve arms and the
approval-carrying `templates::spawn`. The swarm path (deploy request or
wanted-state sweep -> queue_first_deploy -> templates::first_deploy) used
none of them. Old `spawn` approval rows are skipped by collect_lenient,
as `init_config` rows were in a3b672d1.

policy.rs's comment on agent_object_name stated swarm-wide name
uniqueness as a fact; it now says where it is enforced and what that
check cannot see.

Refs #4396
2026-09-29 15:47:40 +02:00
..
agent.rs swarm-queue-client: one agent-token spelling, and no hive in AgentCredential 2026-09-28 08:24:52 +02:00
forge.rs swarmctl: forge make-admin 2026-09-25 08:29:56 +02:00
main.rs Make agent creation swarm-only and refuse a name placed on another hive 2026-09-29 15:47:40 +02:00
users.rs swarmctl: add user reset-password 2026-09-29 12:31:21 +02:00