fleetd #103: document systemd worker secrets #262

Closed
agent wants to merge 0 commits from worker/fleetd-103-23a113-6 into main
Member

Route B: document every required secret. I chose it because it is the safer default: it needs no zsh or secret-store setup on Linux. The unit now tells operators to set FLEETD_API_TOKEN, WORKER_GITEA_TOKEN, and AI_GATEWAY_TOKEN in a private drop-in or 0600 EnvironmentFile. It states the late failure for each worker and gateway token, and tells operators to check journalctl --user -u fleetd for Fleetd.reportRequiredSecrets.

Build: mvn clean install passed. Tests run: 1258, Failures: 0, Errors: 0, Skipped: 0. BUILD SUCCESS.

This was not checked on a real Linux host because I cannot reach one. I did not run systemctl.

Same-shape note: none spotted within the allowed two-file scope; scripts/fleetd-launchd-wrapper.sh already documents both tokens.

Route B: document every required secret. I chose it because it is the safer default: it needs no zsh or secret-store setup on Linux. The unit now tells operators to set FLEETD_API_TOKEN, WORKER_GITEA_TOKEN, and AI_GATEWAY_TOKEN in a private drop-in or 0600 EnvironmentFile. It states the late failure for each worker and gateway token, and tells operators to check journalctl --user -u fleetd for Fleetd.reportRequiredSecrets. Build: mvn clean install passed. Tests run: 1258, Failures: 0, Errors: 0, Skipped: 0. BUILD SUCCESS. This was not checked on a real Linux host because I cannot reach one. I did not run systemctl. Same-shape note: none spotted within the allowed two-file scope; scripts/fleetd-launchd-wrapper.sh already documents both tokens.
agent added 1 commit 2026-09-03 11:23:55 +02:00
fleetd #103: document systemd worker secrets
CI / contract (pull_request) Successful in 1m16s
CI / build (pull_request) Successful in 1m31s
9d0bf14c46
ltms closed this pull request 2026-09-03 11:36:09 +02:00
Some checks are pending
CI / contract (pull_request) Successful in 1m16s
CI / build (pull_request) Successful in 1m31s

Pull request closed

Sign in to join this conversation.