The mesh owns the operator's ~/.ssh: account fact + home-scoped resources (to-be 29) #86

Merged
jschoubben merged 1 commits from feat/to-be-29-mesh-owns-ssh into main 2026-09-27 15:51:55 +00:00
Owner

The controller half of to-be 29:

  • Account fact — a node carries its operator account (name + home): migration 0036, Node.Account/AccountHome, Node.Home() derivation, inventory.SetAccount, and a node account <name> <account> [home] CLI.
  • Machine facts — ${machine:account} / ${machine:account-home}, and machineInto now resolves ${machine:…} in a resource's path and owner (not just content), so a module can place ~/.ssh at a home it can't hardcode.
  • Home-scoped roster file — RosterFile.Home: the file lands under this node's account home, chowned to the account; the template sees each node's Account; a machine with no account gets none. Rendering.Accounts carries every node's account for the Host-block User line.

Tested: home-fact placement/owner/skip-no-account, machine account facts, and the ssh-client module composed end-to-end (dir 0700, config into a region of ~/.ssh/config, peer Host blocks with User, self skipped). Behaviour-neutral until a node has an account and ssh-client is assigned. Not deployed.

Pairs with the mesh-catalog ssh-client PR (held until deploy).

The controller half of to-be 29: - **Account fact** — a node carries its operator account (name + home): migration `0036`, `Node.Account`/`AccountHome`, `Node.Home()` derivation, `inventory.SetAccount`, and a `node account <name> <account> [home]` CLI. - **Machine facts** — `${machine:account}` / `${machine:account-home}`, and `machineInto` now resolves `${machine:…}` in a resource's **path and owner** (not just content), so a module can place `~/.ssh` at a home it can't hardcode. - **Home-scoped roster file** — `RosterFile.Home`: the file lands under this node's account home, chowned to the account; the template sees each node's `Account`; a machine with no account gets none. `Rendering.Accounts` carries every node's account for the Host-block `User` line. Tested: home-fact placement/owner/skip-no-account, machine account facts, and the **ssh-client module composed end-to-end** (dir 0700, config into a region of `~/.ssh/config`, peer Host blocks with `User`, self skipped). Behaviour-neutral until a node has an account and ssh-client is assigned. **Not deployed.** Pairs with the mesh-catalog `ssh-client` PR (held until deploy).
jschoubben added 1 commit 2026-09-27 15:51:49 +00:00
A node carries its operator account (name + home; migration 0036, Node.Account,
SetAccount, 'node account' CLI). The account and its home are offered as
machine facts ${machine:account} / ${machine:account-home}, and machineInto
now resolves placeholders in a resource's path and owner (not just content), so
a module writes into a person's home naming what it cannot know. A RosterFile
gains Home: the file is placed under the account's home and chowned to it, its
template sees each node's Account, and a machine with no account gets none —
this is how the ssh Host blocks for every node reach a person's ~/.ssh. Roster
carries per-node accounts (Rendering.Accounts). Tested, including ssh-client
composed end-to-end. Not deployed.
jschoubben merged commit e7b5100324 into main 2026-09-27 15:51:55 +00:00
jschoubben deleted branch feat/to-be-29-mesh-owns-ssh 2026-09-27 15:51:55 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#86