The harness now reads swarm/agents/<agent>/queue from the store itself, under the agent's own store certificate, and holds it in memory only. It reads once before the first connect and again on every reconnect attempt (async-nats `ConnectOptions::with_auth_callback`), so an agent whose secret was re-minted reconnects with the new value instead of being refused until the container restarts. hive-agent-queue-credential.service, the /run file it wrote, and HIVE_AGENT_QUEUE_AGENT_SECRET_FILE are gone; queue-identity.nix now hands hive-agent.service the store address, its certificate paths and the agent name. A failed or empty read before the first connect still falls back to the hive's shared client. Each read is bounded by a 10s timeout, and retries wait out the existing reconnect backoff (500ms doubling, capped at 60s). Closes #4783
80 lines
2.2 KiB
Nix
80 lines
2.2 KiB
Nix
# `checks.script-test-agent-bao-fetch` — runs the agent unit that logs in to
|
|
# the swarm secret store and fetches a secret, ../agent-modules/forge-token.nix,
|
|
# against a stub `bao`. The cases are in ./agent-bao-fetch.sh.
|
|
#
|
|
# What runs is the unit's rendered `ExecStart`, on the unit's own `PATH` with
|
|
# the stub in front. The one edit is the unit's `/run/<unit>/` prefix, moved
|
|
# under the build directory because the sandbox has no writable `/run`.
|
|
{
|
|
pkgs,
|
|
lib,
|
|
self,
|
|
nixosSystem,
|
|
}:
|
|
let
|
|
inherit
|
|
(import ../module-eval/lib.nix {
|
|
inherit
|
|
pkgs
|
|
lib
|
|
self
|
|
nixosSystem
|
|
;
|
|
})
|
|
agentWith
|
|
;
|
|
|
|
machine = agentWith { services.hyperhive.agent.bao.addr = "https://bao.t.local:8200"; };
|
|
|
|
unitEnv =
|
|
prefix: name:
|
|
let
|
|
u = machine.systemd.services.${name};
|
|
in
|
|
{
|
|
"${prefix}_UNIT" = name;
|
|
# `removeSuffix`, not `trim`: `trim` drops the string context, and with it
|
|
# the script's store path from this check's inputs.
|
|
"${prefix}_SCRIPT" = lib.removeSuffix " " u.serviceConfig.ExecStart;
|
|
"${prefix}_PATH" = u.environment.PATH;
|
|
"${prefix}_BAO_ADDR" = u.environment.BAO_ADDR;
|
|
};
|
|
|
|
# Answers `login` and `kv get` from `FAKE_BAO_*` variables and logs every
|
|
# call. A `kv` call without the token `login` printed fails, so a script that
|
|
# drops `BAO_TOKEN` between the two cannot pass.
|
|
fakeBao = pkgs.writeShellScriptBin "bao" ''
|
|
echo "$*" >> "$FAKE_BAO_LOG"
|
|
case "$1" in
|
|
login)
|
|
printf '%s' "$FAKE_BAO_LOGIN_ERR" >&2
|
|
printf '%s' "$FAKE_BAO_LOGIN_OUT"
|
|
exit "$FAKE_BAO_LOGIN_RC"
|
|
;;
|
|
kv)
|
|
if [ "''${BAO_TOKEN-}" != "$FAKE_BAO_LOGIN_OUT" ]; then
|
|
echo "fake bao: kv called without the login's token" >&2
|
|
exit 97
|
|
fi
|
|
printf '%s' "$FAKE_BAO_KV_ERR" >&2
|
|
printf '%s' "$FAKE_BAO_KV_OUT"
|
|
exit "$FAKE_BAO_KV_RC"
|
|
;;
|
|
*)
|
|
echo "fake bao: unexpected call: $*" >&2
|
|
exit 98
|
|
;;
|
|
esac
|
|
'';
|
|
in
|
|
pkgs.runCommand "hyperhive-script-test-agent-bao-fetch"
|
|
(
|
|
unitEnv "FORGE" "hive-agent-forge-token"
|
|
// {
|
|
FAKE_BAO_BIN = "${fakeBao}/bin";
|
|
}
|
|
)
|
|
''
|
|
${pkgs.bash}/bin/bash ${./agent-bao-fetch.sh}
|
|
touch "$out"
|
|
''
|