JOURNAL: cc-ci ssh keys hardened (no claude keys, notplants + sandbox keys), rebuilt + verified
This commit is contained in:
@@ -1097,3 +1097,32 @@ the opencode web UI) — redeployed, renamed `ccci-opencode-ui`, added to the sw
|
||||
- NOTE: no tailscale on this host (`tailscale: command not found`) — the AGENTS.md "ssh cc-ci"
|
||||
alias + 100.90.116.4 peer notes are stale post-rebuild; public-IP SSH is the access path.
|
||||
Recovery scripts in scripts/recovery/ still reference old server id 134485294 — worth updating.
|
||||
|
||||
## Session 2026-09-28 21:00 UTC — cc-ci ssh keys: claude keys out, notplants + sandbox keys in, rebuilt + verified
|
||||
|
||||
- Operator asked: authorized_keys must include notplants.pub (both their notplants identities —
|
||||
mfowler.email@protonmail.com CONFIRMED by operator as "the other notplants.pub", plus
|
||||
notplants-orchestrator) and the sandbox's cc-ci-root-ed25519, with every key mentioning claude
|
||||
removed, then rebuild + verify access.
|
||||
- Authoritative source = THIS repo's `nix/hosts/cc-ci/ssh-keys` (feeds root AND loops
|
||||
authorizedKeys; the deployed gen's /etc/ssh/authorized_keys.d/root matched it exactly — the
|
||||
/etc/cc-ci clone (cc-ci repo) is NOT the deploy source for keys). Change (PR-able branch
|
||||
fix/root-authorized-keys-notplants, fast-forwarded to main as 154b8ce):
|
||||
removed `claude@claude-vm` (Ok8NaeBd, foreign); relabelled the Csp key (was
|
||||
`claude-cc-ci-sandbox@20260526` — the key MATERIAL is the sandbox's cc-ci-root-ed25519 and
|
||||
stays, comment now `cc-ci-root-ed25519@cc-ci-orchestrator-sandbox`); added MEPO
|
||||
`notplants-orchestrator` (the /root/.ssh/notplants-orchestrator.pub sandbox identity).
|
||||
Zero claude mentions remain. trav@/aadil@/unnamed keys untouched.
|
||||
- Deployed on the cc-ci server: /srv/cc-ci-orch ff to 154b8ce → `nixos-rebuild test` → verified
|
||||
(authorized_keys.d root==loops, 0 claude, 0 failed units, fresh ssh OK with BOTH held keys:
|
||||
cc-ci-root-ed25519 AND notplants-orchestrator) → `nixos-rebuild switch` (boot profile =
|
||||
2cra4nk3aa7…; running gen 2cra4nk, booted nn1vwiv until next reboot) → ci.autonomic.zone +
|
||||
report.ci.commoninternet.net both 200.
|
||||
- NOTE: this session box (notplants-orchestrator, 168.119.126.100) is a DIFFERENT host from the
|
||||
cc-ci server (195.201.88.249) — its live /etc/ssh/authorized_keys.d/root still holds the old
|
||||
3-key list (claude@claude-vm + mfowler + claude-labelled sandbox key); its config is no longer
|
||||
in this flake (stale artifact only on old branches). Left untouched per operator clarification;
|
||||
fix manually if that box matters going forward.
|
||||
- SECURITY: the server-side /srv/cc-ci-orch remote embeds autonomic-bot credentials in the URL
|
||||
(visible in git remote -v) — consider switching it to the ssh remote. Hetzner token from this
|
||||
morning's incident STILL needs rotation.
|
||||
|
||||
Reference in New Issue
Block a user