Skip to main content
← Back to list
01Issue
FeatureClosedSwamp ClubPublic
AssigneesNone

Relationships

#2934 Docs: account-requirement manual page after the auth gate follow-ups (swamp-club#2916)

Opened by stack72 · 10/2/2026

Follow-up to swamp-club#2916 (swamp PR #2786, merged 2026-10-02). Page: content/manual/reference/swamp-account-requirement.md.

  1. Server error (5xx) row. The page says a run without a proof continues for up to 24 hours from the first error. That holds only when swamp can write its config dir. When the dir is read-only, or the process does not own it (a system serve or worker daemon running as root against the enabling user's dir), swamp cannot record when the errors started, so each run passes for the whole outage. The warning now says this instead of promising 24 hours. Add a sentence or footnote, and recommend SWAMP_SIGNIN_TOKEN for read-only containers.

  2. Daemons and containers section. A process that does not own the config dir reads it but never writes it: no proof refresh, no scope or identity cache, no identity.json, no autoupdate preferences. Because it cannot cache whoami answers, it calls whoami on every run. This is by design.

  3. JSON output. In --json mode, a run that passes offline now writes one JSON line to stderr, an object with a warning message and authMode set to offline. Stdout carries only the command output. Worth a line wherever offline behaviour is described, or in the CLI output reference.

  4. This page is now the target of the no-account block message (For CI and daemons, see https://swamp-club.com/manual/reference/swamp-account-requirement). Make sure the CI section names SWAMP_API_KEY and SWAMP_SIGNIN_TOKEN and where to create a collective token, and the daemon section says to sign in as the enabling user and re-run swamp serve daemon enable or swamp worker daemon enable.

  5. Optional, troubleshooting: a blocked audit hook (swamp audit record --from-hook) records nothing and exits 0, so an empty audit timeline usually means the gate is blocking. Running any swamp command or swamp auth whoami in the same environment shows the reason. Fits use-the-audit-timeline.md.

The design source of truth is design/surfaces/auth-gate.md in the swamp repo.

02Bog Flow
✓OPEN○TRIAGED○IN PROGRESS◉CLOSED

Closed

10/2/2026, 1:46:26 AM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

system commented 10/2/2026, 12:35:21 AM

Classified automatically when this issue was filed.

  • Source: Swamp Club

If you feel this classification is incorrect, add a ripple to tell us so.

stack72 commented 10/2/2026, 1:46:26 AM

Documented in https://github.com/swamp-club/swamp-club/pull/1281. All five points are covered. (1) reference/swamp-account-requirement.md has a footnote on the 5xx row for when the start of the 24-hour window cannot be recorded (read-only or non-owned config dir), recommending SWAMP_SIGNIN_TOKEN for read-only containers. (2) The daemons section says a non-owning process reads the config dir but never writes it, and so calls whoami on every run. (3) A new 'Offline warnings' table gives the one-line JSON form on stderr; reference/cli-output.md links to it. (4) A new CI section shows the no-account block message and names SWAMP_API_KEY, SWAMP_SIGNIN_TOKEN and where to create a collective token; the daemon section says to sign in as the enabling user and re-run daemon enable. (5) how-to/use-the-audit-timeline.md has a 'timeline stopped filling' section. Messages were taken from auth_gate.ts on swamp main.

Sign in to post a ripple.