README §4b: the bot deploy key is generated on the host; master age key only for the first deploy
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
This commit is contained in:
@@ -34,8 +34,9 @@ can repeat it. Read it once before starting; the order matters.
|
||||
public keys that get root are tracked in `nix/hosts/cc-ci/ssh-keys` (one per line). Password
|
||||
login is disabled and fail2ban watches sshd, so a key is the only way in.
|
||||
- Read access to `recipe-maintainers/cc-ci`, `recipe-maintainers/cc-ci-orchestrator` (both public
|
||||
read) and the **private** `recipe-maintainers/cc-ci-secrets` (the `autonomic-bot` deploy key,
|
||||
`autonomic-bot-gitea-ed25519`, has it).
|
||||
read) and the **private** `recipe-maintainers/cc-ci-secrets` (the `autonomic-bot` account has
|
||||
it; the host gets its own deploy key on that account, §4b/§4c — and the bot password, in
|
||||
`.testenv`, is what registers it).
|
||||
- The out-of-band secrets listed in §4. If you are migrating, they come from the old host; if
|
||||
you are starting fresh you create them (each row says how).
|
||||
- Control of the DNS zone (Gandi for `commoninternet.net`) for the cutover in §7.
|
||||
@@ -170,19 +171,21 @@ traffic is docker-forwarded, not host INPUT).
|
||||
### 4b. The CI server's checkout and its one out-of-band secret
|
||||
|
||||
```bash
|
||||
# root's deploy key for the private cc-ci-secrets submodule
|
||||
# the bot deploy key for the private cc-ci-secrets submodule — generated ON this host by loops
|
||||
# (§4c) and registered on the autonomic-bot Gitea account; root only points at it:
|
||||
install -d -m700 /root/.ssh
|
||||
install -m600 <autonomic-bot-gitea-ed25519> /root/.ssh/autonomic-bot-gitea-ed25519
|
||||
cat > /root/.ssh/config <<'EOF'
|
||||
cat > /root/.ssh/config <<'SSHCFG'
|
||||
Host git.autonomic.zone
|
||||
Port 2222
|
||||
User git
|
||||
IdentityFile /root/.ssh/autonomic-bot-gitea-ed25519
|
||||
IdentityFile /secrets/files/autonomic-bot-cc-ci-ed25519
|
||||
IdentitiesOnly yes
|
||||
EOF
|
||||
SSHCFG
|
||||
# the deployed checkout: nightly-sweep runs from it, sops reads secrets/secrets.yaml from it
|
||||
git clone --recursive https://git.autonomic.zone/recipe-maintainers/cc-ci.git /etc/cc-ci
|
||||
# the master (recovery) age key — the only sops recipient a fresh host can be
|
||||
# the age identity sops-nix decrypts with. FIRST deploy of a host that is not yet a recipient:
|
||||
# the master (recovery) key, temporarily. Once the host is a recipient (below): its own
|
||||
# ssh-host-key-derived identity, and the master key leaves the box.
|
||||
install -d -m700 /var/lib/sops-nix
|
||||
install -m600 <master-age.txt> /var/lib/sops-nix/key.txt
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user