forked from heavy-duty/rig
The previous commit restarted ssh and only checked `sshd -T` afterwards. On a box whose only door is SSH, restarting against a config sshd refuses to parse leaves no listener and no way back in — the same shape as the firewall-before- bootstrap lockout this session already found in the migration runbook: commit to the irreversible act, then verify. Now `sshd -t` parses the MERGED config (our drop-in, cloud-init's, and any third-party file) before the restart; on failure the drop-in is rolled back and the daemon is left untouched. Verified: a bad neighbour drop-in exits 255 and never reaches `systemctl restart`. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| bootstrap.sh | ||
| coolify-install.sh | ||
| runner-install.sh | ||