Resolve the identity name to authenticate as. Priority: 1. An explicit override (the `--identity` flag). 2. URL userinfo (`http://bob@host/...`). 3. A configured server profile whose host is the longest dot-boundary suffix of the remote host (`[servers.prod] url=... identity=...`). This is the binding that makes pushes to *any* tenant under a server you've registered with ("just works" without `-
(
remote_url: &str,
identity_override: Option<&str>,
)
| 75 | /// Returns `None` only when there is no override and nothing inferable from the |
| 76 | /// URL or config. |
| 77 | fn resolve_identity_name_with_override( |
| 78 | remote_url: &str, |
| 79 | identity_override: Option<&str>, |
| 80 | ) -> Option<String> { |
| 81 | if let Some(name) = identity_override { |
| 82 | return Some(name.to_string()); |
| 83 | } |
| 84 | // A CI runner has no config to bind and no interactive step to write one; |
| 85 | // an env var is the only handle it has. Behind --identity, ahead of config, |
| 86 | // because a runner setting it means it. |
| 87 | if let Ok(name) = std::env::var(AGENT_IDENTITY_ENV) { |
| 88 | let name = name.trim(); |
| 89 | if !name.is_empty() { |
| 90 | log::debug!("Using agent identity from {AGENT_IDENTITY_ENV}: {name}"); |
| 91 | return Some(name.to_string()); |
| 92 | } |
| 93 | } |
| 94 | resolve_identity_from_url(remote_url, &configured_server_identity_bindings()) |
| 95 | } |
| 96 | |
| 97 | /// Collect the server profiles from the global config — both the default |
| 98 | /// `[server]` block and every named `[servers.*]` profile — that declare an |