forked from heavy-duty/rig
#17's table said runner 'can close root once an admin user is proven'; the class model (#26) superseded the per-role call, and close-root refuses on class=server — runner's class. The gate does not change: the refusal message now explains itself (server-class machines are automation identities whose management plane IS root SSH; a CI box meant to be administered like a human machine is --class human at bootstrap, not an exception), and the README's identity-model section records the divergence in one paragraph. README also documents the @root seed token and close-root's reachability proofs. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| lib | ||
| bootstrap.sh | ||
| coolify-backup-install.sh | ||
| coolify-install.sh | ||
| db.sh | ||
| runner-install.sh | ||
| runner-remove.sh | ||
| runner-repoint.sh | ||
| runner-status.sh | ||
| users-apply.sh | ||
| users-close-root.sh | ||
| users-status.sh | ||