15 · Token lifecycle
The auth code path exercised end to end on a control plane that is not in open mode. An admin token mints a client token, the CLI saves it, and a Python worker consumes it from the environment.
Starting with a new server? Follow Setting Up Lakeshore Service for the full setup sequence.
Exercises
LAKESHORE_ADMIN_TOKENon the control-plane side — admin-bearer validation.lakeshore admin tokens create— the explicit mint path.lakeshore auth login— both the--tokenpath and the admin-mint-on-the-fly path, saving toauth.yml.LAKESHORE_CLIENT_TOKEN— the env var the Python worker reads, independent ofauth.yml.
Requires
- A control plane with
LAKESHORE_ADMIN_TOKENset (so it is not in open mode). For details, see Auth and secrets. LAKESHORE_URLunset while you test the token path — when it is set, non-authcommands send no bearer token at all.
Run
Then drive a worker from the environment alone — no auth.yml
involved:
lakeshore worker never reads ~/.config/lakeshore/auth.yml. The
plane it drains has to come from --url / LAKESHORE_URL, and the
token from --token / LAKESHORE_CLIENT_TOKEN. That is why this step
re-exports the token explicitly rather than relying on step 1.
Expected output
lakeshore auth status:
worker once starts, drains at most one job, and exits without
authentication errors.
If it fails
| Symptom | Likely cause |
|---|---|
error: LAKESHORE_ADMIN_TOKEN is required for admin commands. | Not exported in this shell. Every admin subcommand hard-exits 1 without it. |
mint failed (401) on auth login | The control plane doesn't recognize the admin token. Make sure your shell value matches what the CP read from .env at boot, and restart the CP after changing .env. |
whoami failed (403) | The token is scoped to a different namespace than --namespace. |
authMode: open | The CP booted with a blank LAKESHORE_ADMIN_TOKEN and enforces nothing. Set it and restart. |
| The worker authenticates as nobody | LAKESHORE_CLIENT_TOKEN is empty. Re-export it from auth.yml. |
Status
Manual.
Loop back
That's the full cascade. Once all 15 are green you have working verification of every major surface. Re-run as features change.
→ Back to Overview