forked from heavy-duty/rig
The headline of #17: rig can verify a lot locally, but never that the operator HOLDS the admin's private key. Seeding authorized_keys from root's current /root/.ssh/authorized_keys turns that unprovable claim into a proven one — the operator is connected as root right now using one of those keys. The users file gains the literal key-field token '@root', shape-validated in the parse pass (exit 2, pre-root-check, testable non-root); apply resolves it once after the root check, dies with the repair when root has no keys to seed, copies key lines verbatim (options included — rig will not silently widen what a key can do), and writes seeded keys first with literal lines appended, so the cmp-guard keeps re-runs convergent to root's then-current keys plus the literals. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| runner-config.sh | ||
| users-config.sh | ||