Issued attic tokens by default: nodes join with no secret files #31

Manually merged
krisbuild merged 1 commit from auto-attic-tokens into main 2026-09-29 23:55:10 +02:00
Owner

Joining a build node no longer needs a secret file. Add the agent and cache-client options, switch, and approve the node in the UI.

Until now, #13's per-node attic tokens never reached any node. issueAgentTokens was off, and even with it on, agents declared trust 0 and approvals defaulted to 0, below cache_push_min_trust = 1.

  • Trust: a token-holding agent declares the most its token allows (a tokenless agent still declares 0), so the operator's grant decides.
  • Approval defaults: minting and approval default to max_trust = 1, an ordinary build node that may push. 0 means build-only.
  • Editing trust: an admin can change an unrevoked token's max_trust in place (POST /api/agent-tokens/{id}/trust, plus a form on /ui/tokens). Live sessions are closed as on revocation and re-admitted at the new cap, which re-decides their attic token.
  • Module: cache.server.issueAgentTokens defaults to on when the control plane runs on the cache host. cache.client.tokenFile is optional, and leaving it unset is now the usual case.

🤖 Generated with Claude Code

Joining a build node no longer needs a secret file. Add the agent and cache-client options, switch, and approve the node in the UI. Until now, #13's per-node attic tokens never reached any node. `issueAgentTokens` was off, and even with it on, agents declared trust 0 and approvals defaulted to 0, below `cache_push_min_trust = 1`. - **Trust:** a token-holding agent declares the most its token allows (a tokenless agent still declares 0), so the operator's grant decides. - **Approval defaults:** minting and approval default to `max_trust = 1`, an ordinary build node that may push. 0 means build-only. - **Editing trust:** an admin can change an unrevoked token's `max_trust` in place (`POST /api/agent-tokens/{id}/trust`, plus a form on `/ui/tokens`). Live sessions are closed as on revocation and re-admitted at the new cap, which re-decides their attic token. - **Module:** `cache.server.issueAgentTokens` defaults to on when the control plane runs on the cache host. `cache.client.tokenFile` is optional, and leaving it unset is now the usual case. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Issued attic tokens by default: a node joins with no secret files
All checks were successful
krisbuild/kris/krisbuild/nix/hello cached
krisbuild/kris/krisbuild/nix/test-deps cached
krisbuild/kris/krisbuild/nix/workspace-deps cached
krisbuild/kris/krisbuild/nix/world cached
krisbuild/kris/krisbuild/nix/clippy succeeded
krisbuild/kris/krisbuild/nix/test succeeded
krisbuild/kris/krisbuild/nix/build succeeded
krisbuild/kris/krisbuild/nix/kb-check succeeded
krisbuild/kris/krisbuild/nix/deployed succeeded
krisbuild/kris/krisbuild krisbuild kris/krisbuild: all tasks succeeded
krisbuild/queue merged
336deee74e
A token-holding agent now declares the most its token allows (u8::MAX)
unless configured otherwise, so the operator's grant is its trust; a
tokenless agent still declares 0. Minting and approval default to
max_trust 1, an ordinary build node that may push to the cache (0 is
build-only), and the forms say so.

An unrevoked token's max_trust can be changed in place (admin-only:
POST /api/agent-tokens/{id}/trust, and a form on /ui/tokens). Sessions
admitted under another cap are closed like on revocation, with the same
born-closed rule for one verified before the change; the agent
reconnects and is re-admitted at the new cap, which re-decides its attic
token.

Module: cache.server.issueAgentTokens defaults to on when the control
plane runs on the cache host; cache.client.tokenFile stays optional and
unset is the usual case. The module check covers a joining node on its
issued token and the server host rendering [attic].

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Author
Owner

CI green on this head.

@krisbuild r+

CI green on this head. @krisbuild r+
krisbuild manually merged commit 66a59afafd into main 2026-09-29 23:55:10 +02:00
Collaborator

Merged as 66a59afafd.

Merged as 66a59afafd7a.
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kris/krisbuild!31
No description provided.