Operator: no ssh keys or non-essential secrets from the old orchestrator box on the cc-ci host. `ssh cc-ci` uses cc-ci-local-ed25519 (generated on the host, pub in nix/hosts/cc-ci/ssh-keys); pushes to Gitea use autonomic-bot-cc-ci-ed25519 (generated on the host, registered on the bot account); root reuses that file for the cc-ci-secrets submodule. README §4: the /secrets/files inventory shrinks to exactly what cc-ci needs, and §4b now says to make the host a sops recipient and take the master key away. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz