forked from heavy-duty/rig
The headline of #17: rig can verify a lot locally, but never that the operator HOLDS the admin's private key. Seeding authorized_keys from root's current /root/.ssh/authorized_keys turns that unprovable claim into a proven one — the operator is connected as root right now using one of those keys. The users file gains the literal key-field token '@root', shape-validated in the parse pass (exit 2, pre-root-check, testable non-root); apply resolves it once after the root check, dies with the repair when root has no keys to seed, copies key lines verbatim (options included — rig will not silently widen what a key can do), and writes seeded keys first with literal lines appended, so the cmp-guard keeps re-runs convergent to root's then-current keys plus the literals. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| lib | ||
| bootstrap.sh | ||
| coolify-backup-install.sh | ||
| coolify-install.sh | ||
| db.sh | ||
| runner-install.sh | ||
| runner-remove.sh | ||
| runner-repoint.sh | ||
| runner-status.sh | ||
| users-apply.sh | ||
| users-close-root.sh | ||
| users-status.sh | ||