#cloud-config # A thin, creds-free, server-class seed (#81): the 'ops' user, tmux (#65), # and rig — nothing that joins a tailnet or admits credentials, no docker, # no sshd config, no keys. The server posture comes from # 'rig bootstrap staging-box' (heavy-duty/rig#31), which box auto-runs after # mint; the tailnet workload join holds a pre-auth key and stays # operator-run ('box shell' → 'sudo rig bootstrap workload-server'), exactly as # #69 designed it — box never sees the key. users: - name: ops shell: /bin/bash sudo: "ALL=(ALL) NOPASSWD:ALL" lock_passwd: true package_update: true # tmux: 'box tmux' runs 'tmux new-session' INSIDE the box (#65) — and the # operator babysits the workload join through it. # curl + ca-certificates: the rig installer below rides them, and a bare # cloud image is not guaranteed to ship either. packages: - tmux - curl - ca-certificates runcmd: # Preinstall rig so the box can converge — and re-converge — via # 'rig bootstrap staging-box'. @RIG_REPO@/@RIG_REF@ are the pin point (#81): # box substitutes them at mint from the RIG_REPO/RIG_REF environment # (default heavy-duty/rig @ main — unpinned, tracking main, the same # honest edge as rig's own unpinned box install, until rig#32 ships a # release flow). The pin covers both the installer fetched AND the tree # it installs, so a branch under review is testable end to end. # HOME=/root: cloud-init runs runcmd as root but with NO $HOME in the # environment, and the rig installer (set -u) reads $HOME for its DEST — # measured live: the mint died with "HOME: unbound variable" without it. - curl -fsSL https://raw.githubusercontent.com/@RIG_REPO@/@RIG_REF@/install.sh | HOME=/root RIG_REPO="@RIG_REPO@" RIG_REF="@RIG_REF@" bash