[ssh, pubkeys] SSH access across the rack nodes using your pubkey(s) - #62
Open
zeeshanlakhani wants to merge 1 commit into
Open
[ssh, pubkeys] SSH access across the rack nodes using your pubkey(s)#62zeeshanlakhani wants to merge 1 commit into
zeeshanlakhani wants to merge 1 commit into
Conversation
Previous to this changeset, ssh'ing into rack nodes within a topology allowed empty-password root login and permissive defaults. This work enables ordinary key-based access to every guest; all without manually installing it on each node. voxel will now handle key replacement and discovery, permissions, and repeated boot without duplicate entries. This is an operator convenience that came up for me during multiple voxel runs and debug situations. ### Follow-up work - Disabling root-password login, with a plan for keyless setups and recovery. I didn't want to flip login behavior in this changeset, since keyless setups still lean on the empty password we've had. - Migrating automated SSH/SCP clients to key auth. - Verifying usable credentials further.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previous to this changeset, ssh'ing into rack nodes within a topology allowed empty-password root login and permissive defaults.
This work enables ordinary key-based access to every guest; all without manually installing it on each node. voxel will now handle key replacement and discovery, permissions, and repeated boot without duplicate entries.
This is an operator convenience that came up for me during multiple voxel runs and debug situations.
Follow-up work