sshd: the operator's door is a module #107

Merged
jschoubben merged 1 commits from feat/sshd-module into main 2026-09-26 18:15:09 +00:00
Owner

The spec is the working system: HAL's 99-hal.conf, restated as 10-mesh.conf so lexical include order makes the mesh's answer win while the predecessor's file is still on disk. Subsystem stays the stock config's (first-set wins, and it sits before the Include). Port 22 from anywhere, said in listens with its reason: the machines that need the door are exactly the ones not on the mesh yet, and locking the operator out is the one failure a firewall must never arrange.

The spec is the working system: HAL's `99-hal.conf`, restated as `10-mesh.conf` so lexical include order makes the mesh's answer win while the predecessor's file is still on disk. `Subsystem` stays the stock config's (first-set wins, and it sits before the Include). Port 22 from anywhere, said in `listens` with its reason: the machines that need the door are exactly the ones not on the mesh yet, and locking the operator out is the one failure a firewall must never arrange.
jschoubben added 1 commit 2026-09-26 18:15:02 +00:00
The spec is the working system: HAL's 99-hal.conf, restated as
10-mesh.conf so lexical include order makes the mesh's answer the one
that wins while the predecessor's file is still on disk. Subsystem
stays the stock config's — first-set wins and it sits before the
Include. Port 22 from anywhere, said in listens with its reason: the
machines that need the door are exactly the ones not on the mesh yet,
and locking the operator out is the one failure a firewall must never
arrange.
jschoubben merged commit fd9be011c0 into main 2026-09-26 18:15:09 +00:00
jschoubben deleted branch feat/sshd-module 2026-09-26 18:15:09 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#107