Skip to content

feat(agent): register the executor token with NetPulse at startup - #412

Merged
gnacho merged 1 commit into
mainfrom
feat/411-reg-token
Sep 23, 2026
Merged

gnacho merged 1 commit into
mainfrom
feat/411-reg-token

Conversation

@gnacho

@gnacho gnacho commented Sep 23, 2026

Copy link
Copy Markdown
Owner

NetPulse can only delegate ops to a NetGrip router when it knows the router's
executor token, and until now that token only travelled with a configuration
backup upload. Routers that never uploaded one could not be orchestrated.

On agent start, NetGrip now posts its executor token to NetPulse's
/api/agents/executor-token with the agent credentials it already has,
fail-silent. NetPulse stores it in kv, so the orchestration (and the MQTT
propagation) works without any prior backup.

Closes #411

@gnacho
gnacho merged commit d3b57a4 into main Sep 23, 2026
1 check passed
@gnacho
gnacho deleted the feat/411-reg-token branch September 23, 2026 21:14
borky pushed a commit to borky/netgrip that referenced this pull request Sep 24, 2026
This fork sends no identifying data anywhere. The sibling project
upstream added an anonymous daily instance ping with a persistent id
(netpulse #822, on by default). Nothing like it exists in this panel;
this makes sure nothing like it arrives through a sync.

Two new fork-only tests, which being new files cannot conflict:

- A source scan fails on any mention of the projects' domain other than
  the announcements feed, and on any reference to NetPulse's telemetry
  switch. The domain match catches a new host and a host name split
  across strings, and the allowed feed is matched as a whole quoted
  literal so nothing can be tacked onto it. It reads source rather than
  asking the toolchain what it would link: this binary ships for ARM and
  MIPS routers, and a dependency-graph check sees only the host
  platform. It fails if it scans implausibly few files.
- A request test covers what a source scan cannot. The feed is the one
  allowed call home, so it is where a new one would most likely be built
  onto the request in code. It drives the real StartAnnouncements
  against a local server and fails unless the request is a plain GET of
  the static file - proven against an id appended by the caller, an
  extra header and an id folded into the user agent.

FORK.md records the policy and an outbound check to run at every sync.
It compares against the develop last pushed, so it still answers
correctly partway through a sync, and matches any URL scheme - MQTT is
tcp:// - and it says plainly what no pattern can see: a URL built at
runtime, like the executor-token call from upstream gnacho#412, which is also
recorded under upstream behaviour accepted as-is.
borky pushed a commit to borky/netgrip that referenced this pull request Sep 26, 2026
This fork sends no identifying data anywhere. The sibling project
upstream added an anonymous daily instance ping with a persistent id
(netpulse #822, on by default). Nothing like it exists in this panel;
this makes sure nothing like it arrives through a sync.

Two new fork-only tests, which being new files cannot conflict:

- A source scan fails on any mention of the projects' domain other than
  the announcements feed, and on any reference to NetPulse's telemetry
  switch. The domain match catches a new host and a host name split
  across strings, and the allowed feed is matched as a whole quoted
  literal so nothing can be tacked onto it. It reads source rather than
  asking the toolchain what it would link: this binary ships for ARM and
  MIPS routers, and a dependency-graph check sees only the host
  platform. It fails if it scans implausibly few files.
- A request test covers what a source scan cannot. The feed is the one
  allowed call home, so it is where a new one would most likely be built
  onto the request in code. It drives the real StartAnnouncements
  against a local server and fails unless the request is a plain GET of
  the static file - proven against an id appended by the caller, an
  extra header and an id folded into the user agent.

FORK.md records the policy and an outbound check to run at every sync.
It compares against the develop last pushed, so it still answers
correctly partway through a sync, and matches any URL scheme - MQTT is
tcp:// - and it says plainly what no pattern can see: a URL built at
runtime, like the executor-token call from upstream gnacho#412, which is also
recorded under upstream behaviour accepted as-is.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(agent): register the executor token with NetPulse at startup

1 participant