forked from heavy-duty/rig
#17's table said runner 'can close root once an admin user is proven'; the class model (#26) superseded the per-role call, and close-root refuses on class=server — runner's class. The gate does not change: the refusal message now explains itself (server-class machines are automation identities whose management plane IS root SSH; a CI box meant to be administered like a human machine is --class human at bootstrap, not an exception), and the README's identity-model section records the divergence in one paragraph. README also documents the @root seed token and close-root's reachability proofs. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| cli.sh | ||
| db-integration.sh | ||