forked from heavy-duty/rig
class decides root SSH's fate, and this is human's: install /etc/ssh/sshd_config.d/00-rig-users.conf (PermitRootLogin no), where the NAME is the mechanism — sshd_config is first-wins, the Include glob expands lexically, and '-' sorts before '.', so it is read before bootstrap's 00-rig.conf and wins. Gated three ways, no --force: a marker must exist (never shut the root door blind), it must say class=human (on a server root is the control plane's automation identity — closing it severs fleet management), and some rig-admin member must already hold a non-empty authorized_keys (never close the only door). The gate's policy lives in the lib as assert_marker_human so the harness proves every refusal against fixture markers as non-root; RIG_ROLE_MARKER keeps the command pointable at the same fixtures. Apply is bootstrap's validate-then-apply shape verbatim — cmp-guard, sshd -t on the merged config before the restart with rollback, then the sshd -T effective assertion. Bootstrap's own permitrootlogin assertion widens to accept 'no': the closed door is strictly harder, never broken, and by first-wins bootstrap cannot reopen it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| runner-config.sh | ||
| users-config.sh | ||