Skip to content

w748: accounts list shows only accounts in use; vault entries renamed vault-<person>[-<n>] - #247

Merged
bryding merged 7 commits into
mainfrom
w748-vault-names
Oct 9, 2026
Merged

bryding merged 7 commits into
mainfrom
w748-vault-names

Conversation

@bryding

@bryding bryding commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

What

Accounts list (dashboard and system_status "Claude accounts in use", buildAccounts)

  • An account is listed only when a role or machine is set to use it, or an agent is running on it now (inUse in AccountContext, hostAccountsInUse in server/secrets.ts, index.ts accountsNow):
    • a machine's own login is left out while that machine is in machines.claudeFromVault (or on the host token, useHostClaudeEnv); it returns when the machine leaves the vault;
    • this host's stored login (the "fff-portal login" row) is left out while no role in claudeAccounts is set to "login" and a host token exists;
    • the host token is left out while no role and no machine uses it; vault tokens while no machine is on the vault and no role is set to "vault";
    • a person's own token and the token file are always listed. An agent running on a hidden account keeps it listed until it stops.
  • A vault token's title is vault-lothsahn-1 …EAAA (no vault: prefix); its description ("the token vault: workers, standing on every machine…") is gone; the dashboard's "N agents" and system_status's "agents on it: …" stay. Machine logins keep "m3 login".
  • The usage line says "from rate limits" instead of "from rate-limit headers" (log lines are unchanged).

Rename, end to end

  • deploy/vm/host/vault.sh now names entries vault-<person> (claude-token), vault-<person>-<n> (claude-tokens/), vault-<person>-github (kept in the same scheme so everything the sync manages starts with vault-).
  • Carry-over without re-entering tokens: fffctl vault put --name vault-ben-1 finds the host-… entry holding the same token and renames it (Vault.rename, also fffctl vault rename OLD NEW): id, token, owner, grants, meters and sessions' last pick stay. A sync against a portal that cannot rename yet changes nothing and warns; an old entry is never removed while its file exists; one left beside its new entry (file changed meanwhile) is removed. Two files that would make one name: the first wins, the other is warned.
  • The server never parsed the host- names (ownership is the entry's owner), so only the sync, the CLI, docs and tests change.

Workers role on the portal host (added by Lothsahn, w748): since w510 the portal runs no workers, so claudeAccounts.workers applies only if a worker daemon runs on the portal's own host (a machine added local). With none, the " login (workers)" account row, "workers here: …" in the per-agent line and the "WARNING: set to the login (workers), which cannot run agents" are left out (workersHere, shownRoles(cfg, workersHere), hostAccountsInUse(cfg, workers)); they return when a local machine is added. Test: accounts.test.ts both cases.

Docs: docs/vault.md (3b), docs/accounts.md. Tests: usage.test.ts (hiding rule both ways, live session keeps it, no inUse = as before, status line), vault.test.ts (rename, CLI put/rename, no value in output), fff-vault-sync.test.sh (rename, old portal, changed file, name clash), ci-vm-e2e.sh (new names).

No portal deploy: the dashboard part is live when Lothsahn deploys; the entries rename at the next fff-vm vault-sync after that.

Request: w748

🤖 Generated with Claude Code

bryding and others added 7 commits October 9, 2026 01:24
… vault-<person>[-<n>]

An account is listed only when a role or machine is set to use it or an agent runs on it
(a machine on the vault hides its own login). A vault token loses the "vault:" prefix and its
description; the usage line says "from rate limits". The host sync names entries
vault-<person>[-<n>]; fffctl vault put renames the old host-... entry holding the same token.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…daemon runs on the portal's own host

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@bryding
bryding merged commit c986812 into main Oct 9, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant