Hub does not revoke the agent credential when a create or launch fails

#2524 · open · 0 comments

View on GitHub ↗

ptone

The delete, suspend and refresh paths all revoke the agent credential they are retiring (handlers_agents_core.go's delete handler, handlers_agent_lifecycle.go's suspendAgent, and the refresh endpoint). A create or launch has no equivalent: once the Hub mints a credential for a create or start dispatch, nothing revokes it if that create or launch then fails - the credential stays valid for its full lifetime regardless of whether the agent ever ran. This affects: - Synchronous create (DispatchAgentCreate) - Provision and reprovision - Create-with-gather, including the case where the broker reports required env vars still missing after gathering (handled as a non-error value today, not a dispatch error) - Finalize-env - A broker launch report that ends in a confirmed failure before the agent ever reaches running (the asynchronous create path) - A start/resume dispatch for a non-running agent - The create-failure cleanup paths that hard-delete an agent row outside the main delete handler (e.g. tearing down a still-provisioning row before recreating it) Expected behavior: every one of these failure paths should revoke the credential it minted, the same way the delete path already does, without masking the original failure if the revoke itself errors.

Comments