Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/swarm-controller/src
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas e04616eb70 swarm-secret-client: agents may list their own subtree; controller rewrites agent policies
render_agent gains a second stanza: list on
secret/metadata/swarm/agents/<agent>/*, next to the existing read on
secret/data/swarm/agents/<agent>/*. An agent can now learn which
credentials it holds by listing its own subtree. Metadata read, writes
and every other principal's paths stay refused.

An agent's policy was only written when it was minted, so existing agents
would never get the new stanza. swarm-controller now rewrites every
agent's policy at start (read_policy::ensure_agent_policies), with the
same 30s / 24h retry as ensure_hive_access. The roster is the store's
hive-agent-* cert-auth roles, listed with the controller's existing
`list` on auth/cert/certs; the writes use its existing grant on
sys/policies/acl/hive-*. Only the policy is written: mint_and_verify
also reissues the certificate, so the pass does not call it.

Refs #4348
2026-10-01 17:43:28 +02:00
..
forge swarm-controller: fix broken rustdoc intra-doc link to AGENT_TOKEN_NAME 2026-09-29 22:13:32 +02:00
matrix_account matrix: swarm-controller is the only minter 2026-09-30 00:46:46 +02:00
agent_icon.rs swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
agent_identity.rs swarm-secret-client: agents may list their own subtree; controller rewrites agent policies 2026-10-01 17:43:28 +02:00
agent_renewal.rs swarm-controller: first credential-renewal pass waits for the queue connection 2026-09-30 15:46:56 +02:00
agent_state_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
agent_status.rs swarm-ui: add agent start/stop, backed by the wanted-state route 2026-09-02 19:57:04 +02:00
auth.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
config_pr.rs swarm-controller: fix stale route reference in snapshot's doc comment 2026-08-19 22:27:12 +02:00
forge.rs remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
issue_report.rs swarm-controller: answer 404, not 503, for an issue-report on a nonexistent repo 2026-09-24 16:38:47 +02:00
main.rs swarm-secret-client: agents may list their own subtree; controller rewrites agent policies 2026-10-01 17:43:28 +02:00
matrix_account.rs swarm-controller: mint each hive's matrix sender token 2026-09-29 22:14:40 +02:00
otel_http_client.rs swarm-queue-client: request the bearer-authz scope when minting an agent token 2026-09-17 09:51:44 +02:00
queue_identity.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
read_policy.rs swarm-secret-client: agents may list their own subtree; controller rewrites agent policies 2026-10-01 17:43:28 +02:00
status.rs swarm-controller: make status::render/row pub(crate) so agent_status.rs's doc links resolve 2026-09-02 10:20:29 +02:00
store.rs fix doc-comment pointers broken by the module-eval split 2026-09-20 04:31:08 +02:00
term_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
vcs_metrics.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
wanted.rs swarm-controller: first credential-renewal pass waits for the queue connection 2026-09-30 15:46:56 +02:00
webhook.rs swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00