From 048f1b8284701cc8ab31e5df512b420453a94d8b Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 27 Sep 2026 17:50:57 +0200 Subject: [PATCH] ssh-client module: the mesh owns ~/.ssh, config from the hub (to-be 29) Requires openssh; creates ~/.ssh (0700, owned by the operator account via ${machine:account}); writes every other node's Host block (HostName + User ) into a marked region of ~/.ssh/config (home-scoped, into:block), so `ssh ` reaches each peer as the right account and the operator's own config is kept. Universal-tier: assigned wherever a person logs in; a node with no account gets no config. --- modules/ssh-client/module.json | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 modules/ssh-client/module.json diff --git a/modules/ssh-client/module.json b/modules/ssh-client/module.json new file mode 100644 index 0000000..bee0c4f --- /dev/null +++ b/modules/ssh-client/module.json @@ -0,0 +1,26 @@ +{ + "module": "ssh-client", + "version": "1", + "resources": [ + { + "id": "openssh", + "type": "package", + "package": "openssh" + }, + { + "id": "ssh-dir", + "type": "directory", + "path": "${machine:account-home}/.ssh", + "owner": "${machine:account}", + "mode": "0700" + } + ], + "facts": { + "ssh-config": { + "path": ".ssh/config", + "home": true, + "shared": true, + "template": "# The mesh's Host blocks — every other node, so `ssh ` reaches it as the\n# right account. This region is replaced whenever a node joins, leaves or is\n# renamed; the rest of this file is yours and is kept untouched.\n{{range .Machines}}{{if ne .Name $.Node}}\nHost {{.Name}} {{.FQDN}}\n HostName {{.FQDN}}\n{{if .Account}} User {{.Account}}\n{{end}}{{end}}{{end}}" + } + } +}