The live /root/.ssh/authorized_keys on cc-ci had drifted from the declarative users.users.root.openssh.authorizedKeys.keys in nix/hosts/cc-ci-hetzner/configuration.nix — several keys had been added manually and would have been wiped by the next nixos-rebuild switch.
What this does:
syncs the declared list to the live file (10 keys, verified blob-for-blob against the server)
adds the new notplants-orchestrator and nptest keys (both verified working: ssh as root@cc-ci succeeded with the notplants-orchestrator key before this PR)
drops claude-sandbox keys at operator request: the never-live claude@claude-vm key, and one unnamed live key identified as a sandbox key (SHA256:Wlhj5g4IjCId1wvRHnxEiwVVu2N+aYa4gRsY1XfOkts) — removed from the live file in the same change, recoverable from git history if ever needed
Evidence: diff of type+blob between the nix list and the live file is empty (10 == 10); root ssh still authenticates after the live-file edit.
The live `/root/.ssh/authorized_keys` on cc-ci had drifted from the declarative `users.users.root.openssh.authorizedKeys.keys` in `nix/hosts/cc-ci-hetzner/configuration.nix` — several keys had been added manually and would have been **wiped by the next nixos-rebuild switch**.
What this does:
- syncs the declared list to the live file (10 keys, verified blob-for-blob against the server)
- adds the new `notplants-orchestrator` and `nptest` keys (both verified working: ssh as root@cc-ci succeeded with the notplants-orchestrator key before this PR)
- drops claude-sandbox keys at operator request: the never-live `claude@claude-vm` key, and one unnamed live key identified as a sandbox key (`SHA256:Wlhj5g4IjCId1wvRHnxEiwVVu2N+aYa4gRsY1XfOkts`) — removed from the live file in the same change, recoverable from git history if ever needed
Evidence: `diff` of type+blob between the nix list and the live file is empty (10 == 10); root ssh still authenticates after the live-file edit.
The live /root/.ssh/authorized_keys on cc-ci had drifted from this
declarative list: several keys were added manually over time and would
have been wiped by the next nixos-rebuild switch.
- sync the declared list to the live file (10 keys, verified blob-for-blob)
- add the new notplants-orchestrator and nptest keys (added live first)
- drop claude-sandbox keys at operator request (incl. one unnamed live
key identified as a sandbox key, fingerprint SHA256:Wlhj5g4IjCId1wvR
HnxEiwVVu2N+aYa4gRsY1XfOkts) and the never-live claude@claude-vm key
- live file updated in the same change, so state is converged now
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The live
/root/.ssh/authorized_keyson cc-ci had drifted from the declarativeusers.users.root.openssh.authorizedKeys.keysinnix/hosts/cc-ci-hetzner/configuration.nix— several keys had been added manually and would have been wiped by the next nixos-rebuild switch.What this does:
notplants-orchestratorandnptestkeys (both verified working: ssh as root@cc-ci succeeded with the notplants-orchestrator key before this PR)claude@claude-vmkey, and one unnamed live key identified as a sandbox key (SHA256:Wlhj5g4IjCId1wvRHnxEiwVVu2N+aYa4gRsY1XfOkts) — removed from the live file in the same change, recoverable from git history if ever neededEvidence:
diffof type+blob between the nix list and the live file is empty (10 == 10); root ssh still authenticates after the live-file edit.