Per-node attic push tokens issued by the control plane (SPEC §7.3.1) #13
Loading…
Reference in a new issue
No description provided.
Delete branch "attic-tokens"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The control plane issues short-lived, per-node attic tokens over the agent connection (new SPEC §7.3.1). Pushing to the shared cache needs no hand-minted credential on the node.
Control plane
[attic]table:endpoint,cache,token_secret_env,token_validity_secs(default 3600),cache_push_min_trust(default 1). Without the table nothing changes.sub = kb-agent:<node>:token-<id>, pull and push on one cache only,nbfbackdated 60 s. The tests verify tokens withjwt-simpleusing atticd's exact verification options, and pin the claim JSON.cache_push_min_trust. Push access means a node can poison what every other node substitutes, so it is a deliberate grant.Protocol (additive)
CpToAgent::AtticToken(its Debug output hides the token).NodeAd.accepts(serde default). The control plane sends the token only to agents that listattic-tokenthere, so old agents are unaffected. Nodef_hashchange.Agent
config.tomlatomically, mode 0600, under<workDir>/attic/.NixOS module
controlPlane.extraEnvironmentFilesagent.cachePushrenders[cache_push](closes that TODO item)agent.attic.watchStoreruns a watch-store unit askrisbuildthat restarts when the token rotates🤖 Generated with Claude Code
Only
nix/kb-checkfailed, and on infrastructure (the kb-check .drv was not yet in the cache when a node fetched it); tests, clippy, build green.@krisbuild rerun
unknown merge-queue command
rerun.Reviewed: tokens are issued only to token-authenticated connections, after the trust cap and name binding are applied to the Hello (covered by
anonymous_low_trust_and_old_agents_get_none); claims pinned against atticd's own verifier; old agents never receive the message. CI green on rerun (graph 576).@krisbuild r+
Removed from the merge queue: the merge conflicts in crates/kb-agent/src/config.rs.
7fe17aaeb86869993bfbMerged main (#18) and moved
attic_tokensintotests/it/. Build, clippy and kb-check were green on the rebased head (graph 591); its test run was superseded by this push.@krisbuild r+
The pull request head's own build failed (graph 601).
nix/dep/cargo-package-anyhow: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-autocfg: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-binstring: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-byteorder: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-coarsetime: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-const-oid: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-ct-codecs: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-ecdsa: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-hmac: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-hmac-sha256: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-hmac-sha512: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-jwt-simple: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-libm: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-num-bigint: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-num-integer: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-num-iter: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-num-traits: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-pem-rfc7468: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-powerfmt: exit-code on nuxbox, exit 1 — lognix/dep/cargo-package-rand: exit-code on nuxbox, exit 1 — logPush a fix, or comment
@krisbuild retryto rerun the failed tasks and requeue.Removed from the merge queue: the pull-request head changed.
Merged main (#8, #10, #17, #20, #22, #23): kept enrollment's early
work_dirresolution and both connection tests, unified the test harness's header/acceptsconnect helpers. Fully green on this head (graph 651). Off by default (no[attic]table), so it is safe to deploy ahead of any config change.@krisbuild r+
Removed from the merge queue: the merge conflicts in SPEC.md, crates/kb-agent/src/config.rs, crates/kb-agent/src/conn.rs, crates/kb-control-plane/src/agent_auth.rs, crates/kb-control-plane/src/scheduler/matchmaking.rs, crates/kb-control-plane/src/scheduler/sizing.rs, crates/kb-control-plane/src/ws.rs, crates/kb-control-plane/tests/it/common/mod.rs, crates/kb-core/src/node.rs, crates/kb-core/src/protocol.rs.
Merged main (#14, #15, #24, #26).
NodeAd.acceptsis folded into #15's capabilities: the agent advertisesattic-tokenviacaps::advertised, issuance is gated onad.has_cap(caps::ATTIC_TOKEN)(so proto-0 agents never receiveAtticToken), and the hook runs after the trust cap and the handshake's proto check. Nodes without an issued token push exactly as before, so #26's fail-on-push-failure is unaffected. CI green on this head.@krisbuild r+
Removed from the merge queue: the merge conflicts in crates/kb-control-plane/Cargo.toml.
Merged main (#27): the only conflict was
kb-control-plane/Cargo.toml, where #27'sconsoleand this PR'sjsonwebtokenwere added on the same line; both kept, lockfile consistent (cargo check --lockedclean). CI green on this head.@krisbuild r+
Removed from the merge queue: the merge conflicts in Cargo.toml, SPEC.md, crates/kb-agent/src/conn.rs, crates/kb-agent/src/exec.rs, crates/kb-control-plane/Cargo.toml, crates/kb-control-plane/src/ws.rs, flake.nix.
Merged main (#12, #21, #28).
AtticTokenstays an unsequenced control-plane→agent message, outside #21's agent→CP seq/acked_seq accounting; the agent now ignores a token whose expiry isn't newer than the one it holds, so duplicates and reconnect races can't roll it back. Adopted runs (#28) read the token file underwork_dir, which renewal replaces in place. The per-connection renewal task ends on every session exit, including #12's restart close and #21's replacement kick. CI green on this head; priority so it lands before main moves again.@krisbuild r+ p=5
Merged as
e843070652.