Every hive is in a swarm and every swarm runs matrix, so every swarm has a swarm-controller, and since #4810 its hive_sender pass mints each hive's @hive-<hive>: sender token into the store every five minutes. The two other minters of that token go: - swarm-matrix-ctl mint: the systemd.services.swarm-matrix-ctl unit in the hive-matrix container, Command::Mint and src/mint.rs. The binary, its appservice render/publish verbs, ctlPackage, ctlActive and the ctl cert role stay. bao-matrix-reader's checks on the deleted unit are removed; the leaf-identity and no-token-in-env checks now look at swarm-matrix-appservice-publish, which runs under the same identity. - the hive-side mint ladder in hive-c0re's ensure_hive_user (register/appservice-login/password-login with the local as_token), with read_appservice_token, paths::matrix_appservice_token and the helpers only it used. ensure_hive_user now takes the store's token, keeps the file when the store has none or can't be reached, and fails otherwise. - hivectl matrix sync-admin: the verb, HostRequest::MatrixSyncAdmin and handle_matrix_sync_admin. The periodic MatrixSweep (ensure_all) is unchanged apart from no longer reading the local as_token. This removes the double-mint race #4810's review flagged: two minters logging in on one pinned device could leave a dead token in the store until the next pass. Closes #4813 Closes #4814
31 lines
1.2 KiB
Markdown
31 lines
1.2 KiB
Markdown
# swarm-matrix-ctl
|
|
|
|
The rust that runs **inside `containers.hive-matrix`**, beside the homeserver.
|
|
|
|
One binary with subcommands rather than one binary per job. Running code in that
|
|
container is not free: it needs its own store identity, its own cert role and
|
|
its own bind mounts, and every one of those is per-_container_, not per-task. A
|
|
second single-purpose crate would have had to duplicate that plumbing to add one
|
|
action, so the next thing that has to run in here is a **verb**, not a new
|
|
crate.
|
|
|
|
## Verbs
|
|
|
|
### `appservice render`
|
|
|
|
Mints the swarm appservice registration's tokens when absent and renders the
|
|
registration tuwunel loads. Runs before the homeserver and needs no network.
|
|
|
|
### `appservice publish`
|
|
|
|
Writes the rendered `as_token` to the swarm secret store for `swarm-controller`,
|
|
when the store's copy differs.
|
|
|
|
Both are configured entirely by the `MATRIX_APPSERVICE_*` environment the units
|
|
set — no flags. A systemd `Environment=` block is what a nix module can render; a
|
|
command line full of paths is not.
|
|
|
|
## 🩸 A secret is a path, never a value
|
|
|
|
Nothing here logs, prints or interpolates a token. The one identifier this
|
|
binary logs is the store path it wrote.
|