Fix device enrollment contract for RC host - #257
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix the Aether Agent device enrollment request and response to match the deployed Cloud
/device/v1/enrollcontract. The prior CLI sentdisplay_nameandclient, which Cloud rejects with HTTP 422, and expecteddevice_command_key, which Cloud does not return. This blocked the enrolled identity required byaether rc startand Predator #107.The CLI now sends
client_labeland an empty project allowlist, checks the 32-byte command key, and saves the Cloudcommand_key_hexas its existing local device key. The local display name stays local.Verification: build passed; device command and RC suite passed (213 tests); authenticated live enrollment succeeded;
aether rc startopened a real owner-bound RC session and minted an observer invitation without exposing the token in logs. GitHub Actions remain unavailable due account billing lock, so this uses the approved local suite.