Skip to content

fix(agent): drop --org from enrollkey, derive org from the key#30

Merged
taleodor merged 2 commits into
mainfrom
2026-06-enrollkey-drop-org
Jun 7, 2026
Merged

fix(agent): drop --org from enrollkey, derive org from the key#30
taleodor merged 2 commits into
mainfrom
2026-06-enrollkey-drop-org

Conversation

@taleodor-claude

Copy link
Copy Markdown
Contributor

Summary

  • rearm agent enrollkey no longer takes --org. The org is always the one the FREEFORM key resolves to, so requiring it was redundant and a footgun: passing the key-order uuid (the segment after __ord__ in the key ID) instead of the org produced an opaque Not authorized.
  • The CLI now sends no org and uses the new AgentSigningKeyInput.
  • runEnrollkey simplified to the AGENT path; the unreachable committer branch is removed (operator committer enrol stays on the JWT enrollSigningKey mutation).

Requires

Backend: relizaio/rearm-saas#193 (adds AgentSigningKeyInput). Deploy that first — the new mutation arg type won't exist on older backends.

Test plan

  • Against a backend with #193: rearm agent enrollkey --agent <uuid> --format SSH --pubkey-file <f> --identity <email> enrols without --org
  • --help no longer lists --org

taleodor-claude and others added 2 commits June 7, 2026 14:29
The org is always the one the FREEFORM key resolves to, so requiring
--org was redundant and a footgun — passing the key-order uuid (the
segment after __ord__) instead of the org produced an opaque
'Not authorized'. Now the CLI sends no org and uses the new
AgentSigningKeyInput. Simplifies runEnrollkey to the AGENT path
(the unreachable committer branch is removed; operator committer
enrol stays on the JWT mutation).

Co-Authored-By: Claude Opus 4 (1M context) <noreply@anthropic.com>
Match the flag removal — org is derived from the calling key.

Co-Authored-By: Claude Opus 4 (1M context) <noreply@anthropic.com>
@taleodor
taleodor merged commit b3a0c92 into main Jun 7, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants