Relationships
#2740 Docs: describe how enrollment token revoke disconnects connected workers
Opened by stack72 · 9/29/2026
Follow-up to swamp-club#2190.
content/manual/reference/remote-execution/enrollment-tokens.md describes revoked as an immediate cutoff, and its restart table says the orchestrator rejects connection immediately. Before #2190 that was only true at re-enrollment: an already-connected worker stayed connected. After #2190:
- A revoke through the server (swamp worker token revoke --server) disconnects every worker bound to the token straight away, fleet members included, with no reconnection grace window. Their session and dispatch credentials are revoked at once. The response lists them under disconnectedWorkers.
- A revoke from the local CLI (no --server), a revoke on an HA peer, or re-minting the name is picked up by the orchestrator's revalidation pass (every 30s, plus the data poll interval on HA peers).
- A step running on a revoked worker fails with a worker-lost error, following the existing disconnect semantics.
- The worker process stops reconnecting, because a revoked rejection is permanent.
Pages to update: enrollment-tokens.md (state table, the cut-off bullets, and the restart/reboot table row for Token revoked) and the worker-commands reference for swamp worker token revoke output.
Closed
No activity in this phase yet.
stack72 commented 9/29/2026, 10:21:18 PM
Scope addition from #2190: token expiry now uses the same cut-off as revoke. When an enrollment token's lifetime ends, every worker bound to it is removed from the pool at once and its session and dispatch credentials are revoked, with no reconnection grace window (before, the credentials stayed valid for the 60s grace window). The enrollment-tokens.md expiry bullets and the restart/reboot table row for Token expired need the same update as revoke.
stack72 commented 9/29/2026, 11:33:30 PM
Docs fix in swamp-club PR 1265 (one PR covering #2626, #2653, #2661, #2679, #2692, #2694, #2701, #2728, #2733, #2740).
stack72 commented 9/29/2026, 11:35:09 PM
Documented in swamp-club PR 1265. enrollment-tokens.md: the state table, expiry bullets and restart table now describe the cut-off on revoke and on expiry (no grace window, worker stops reconnecting), plus a new Revocation section: --server disconnects bound workers at once and lists them under disconnectedWorkers; local, HA-peer and re-mint revokes are picked up by the 30s revalidation pass (plus the poll interval on HA peers). A step that had written data or is in an affinity group fails; a no-write step is rescheduled. worker-commands.md shows --server revoke output and JSON; security.md recommends revoke --server.
Sign in to post a ripple.