From a85b0ee34611191f8e29387794682723c5aebf10 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 26 Sep 2026 20:14:54 +0200 Subject: [PATCH] sshd: the operator's door is a module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The spec is the working system: HAL's 99-hal.conf, restated as 10-mesh.conf so lexical include order makes the mesh's answer the one that wins while the predecessor's file is still on disk. Subsystem stays the stock config's — first-set wins and it sits before the Include. Port 22 from anywhere, said in listens with its reason: the machines that need the door are exactly the ones not on the mesh yet, and locking the operator out is the one failure a firewall must never arrange. --- modules/sshd/module.json | 39 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) create mode 100644 modules/sshd/module.json diff --git a/modules/sshd/module.json b/modules/sshd/module.json new file mode 100644 index 0000000..6901f80 --- /dev/null +++ b/modules/sshd/module.json @@ -0,0 +1,39 @@ +{ + "module": "sshd", + "version": "1", + "capabilities": [ + "package-manager", + "service-manager" + ], + "listens": [ + { + "port": 22, + "protocol": "tcp", + "from": "anywhere", + "why": "the operator's own door. From anywhere because the machines that need it are exactly the ones not on the mesh yet \u2014 and locking the operator out is the one failure a firewall must never arrange" + } + ], + "resources": [ + { + "id": "package", + "type": "package", + "package": "openssh" + }, + { + "id": "config", + "type": "file", + "path": "/etc/ssh/sshd_config.d/10-mesh.conf", + "mode": "0644", + "content": "# Managed by the mesh (module sshd). Replaced on every push; edit the catalogue instead.\nPort 22\nPermitRootLogin no\nPasswordAuthentication no\nPubkeyAuthentication yes\nKbdInteractiveAuthentication no\nUsePAM yes\nX11Forwarding no\nPrintMotd no\nAcceptEnv LANG LC_*\n" + }, + { + "id": "run", + "type": "service", + "unit": "sshd.service", + "state": "running", + "restart-on": [ + "config" + ] + } + ] +}