The catalogue half of hq to-be 29; the controller half (account fact, home-scoped facts) is mesh-controller#86, merged.
~/.ssh created 0700, owned by the node's operator account (${machine:account} / ${machine:account-home}).
Every other node's Host block (HostName + User <account>) written into a marked region of ~/.ssh/config (home-scoped fact, into: block) — the rest of the file stays the operator's.
A node with no account gets no config.
Rebased onto main 2026-10-03. Verified: go test ./internal/catalogue/ on mesh-controller main with this catalogue beside it — all pass, including TestSSHClientOwnsTheOperatorsSSHConfig. All four nodes have an account recorded (novox jochens, ace ace, shanks/g14 jochen).
Not assigned anywhere by this PR. Note for rollout: nodes still carry HAL's Include ~/.ssh/config.d/mesh and hand-written Host blocks at the top of ~/.ssh/config; ssh takes the first match, so those win over the mesh region until they are removed.
The catalogue half of hq to-be 29; the controller half (account fact, home-scoped facts) is mesh-controller#86, merged.
- `~/.ssh` created 0700, owned by the node's operator account (`${machine:account}` / `${machine:account-home}`).
- Every *other* node's `Host` block (HostName + `User <account>`) written into a marked region of `~/.ssh/config` (home-scoped fact, `into: block`) — the rest of the file stays the operator's.
- A node with no account gets no config.
Rebased onto main 2026-10-03. Verified: `go test ./internal/catalogue/` on mesh-controller main with this catalogue beside it — all pass, including `TestSSHClientOwnsTheOperatorsSSHConfig`. All four nodes have an account recorded (novox jochens, ace ace, shanks/g14 jochen).
Not assigned anywhere by this PR. Note for rollout: nodes still carry HAL's `Include ~/.ssh/config.d/mesh` and hand-written Host blocks at the top of `~/.ssh/config`; ssh takes the first match, so those win over the mesh region until they are removed.
Requires openssh; creates ~/.ssh (0700, owned by the operator account via
${machine:account}); writes every other node's Host block (HostName + User
<account>) into a marked region of ~/.ssh/config (home-scoped, into:block), so
`ssh <node>` reaches each peer as the right account and the operator's own
config is kept. Universal-tier: assigned wherever a person logs in; a node with
no account gets no config.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The catalogue half of hq to-be 29; the controller half (account fact, home-scoped facts) is mesh-controller#86, merged.
~/.sshcreated 0700, owned by the node's operator account (${machine:account}/${machine:account-home}).Hostblock (HostName +User <account>) written into a marked region of~/.ssh/config(home-scoped fact,into: block) — the rest of the file stays the operator's.Rebased onto main 2026-10-03. Verified:
go test ./internal/catalogue/on mesh-controller main with this catalogue beside it — all pass, includingTestSSHClientOwnsTheOperatorsSSHConfig. All four nodes have an account recorded (novox jochens, ace ace, shanks/g14 jochen).Not assigned anywhere by this PR. Note for rollout: nodes still carry HAL's
Include ~/.ssh/config.d/meshand hand-written Host blocks at the top of~/.ssh/config; ssh takes the first match, so those win over the mesh region until they are removed.Requires openssh; creates ~/.ssh (0700, owned by the operator account via ${machine:account}); writes every other node's Host block (HostName + User <account>) into a marked region of ~/.ssh/config (home-scoped, into:block), so `ssh <node>` reaches each peer as the right account and the operator's own config is kept. Universal-tier: assigned wherever a person logs in; a node with no account gets no config.048f1b8284to301aeda5f3