The tenant half of rig#76 is what #123 tracked, but the machine half reaches box in one place: the tailnet workload join box prints as the next step for a staging-box guest is `rig bootstrap workload`, and that role is now `workload-server`. box never runs it -- it holds a pre-auth key, and that it stays operator-run is the absence that keeps box creds-free end to end -- but box does PRINT it, in three places that all had to move together: cmd_new's hint, the staging-box seed's own comment, and the README. A next step an operator copy-pastes is as wrong as a role box executes, and it fails later and further from the cause. The suite's assertion moved with it, so it still pins what it was written to pin: that the join is printed and never exec'd. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
29 lines
1.7 KiB
Bash
29 lines
1.7 KiB
Bash
# The staging-box template — a thin, creds-free, server-class seed (#81, the
|
|
# re-cut of #69's layering): Debian 13, the 'ops' user, tmux and rig. The
|
|
# server posture — docker, sshd hardening — is rig's job: box auto-runs
|
|
# 'rig bootstrap staging-box' after mint (heavy-duty/rig#31). The template is
|
|
# named for the role it converges, suffix and all (heavy-duty/rig#76): rig's
|
|
# roles carry a family suffix — '-server' for fleet machines, '-box' for box
|
|
# tenants — and a seed that named the bare 'staging' would ask a post-rename
|
|
# rig for a role that no longer exists. Server-CLASS, not a fleet machine:
|
|
# this is still a box tenant, so it takes '-box', not '-server'. The tailnet
|
|
# workload join holds a key and therefore STAYS operator-run:
|
|
# box shell <name> # then: sudo rig bootstrap workload-server --hostname <name>
|
|
# KEY="value" only. Parsed against an allowlist, never sourced; there is no
|
|
# key for a network or a security flag, on purpose — the shared box-net
|
|
# profile is the placement contract and no template can weaken it.
|
|
# The two boot demands (#68): the VM is this box's trust boundary and its
|
|
# guest runs docker, so no container fallback (BOX_REQUIRE_VM); and a server
|
|
# must return from a host reboot without an operator (BOX_AUTOSTART).
|
|
# BOX_USER must match the user user-data.yaml creates (the duplication is
|
|
# deliberate and by hand) — and it is the tenant user the rig role converges
|
|
# (rig dies loudly if the seed did not create it).
|
|
BOX_DESCRIPTION="Server-class Debian 13, creds-free — box mints, rig converges, the join stays yours"
|
|
BOX_IMAGE="images:debian/13/cloud"
|
|
BOX_USER="ops"
|
|
BOX_CPU="4"
|
|
BOX_MEMORY="8GiB"
|
|
BOX_DISK="60GiB"
|
|
BOX_REQUIRE_VM="1"
|
|
BOX_AUTOSTART="1"
|
|
BOX_BOOTSTRAP_ROLE="staging-box"
|