Account fact — a node carries its operator account (name + home): migration 0036, Node.Account/AccountHome, Node.Home() derivation, inventory.SetAccount, and a node account <name> <account> [home] CLI.
Machine facts — ${machine:account} / ${machine:account-home}, and machineInto now resolves ${machine:…} in a resource's path and owner (not just content), so a module can place ~/.ssh at a home it can't hardcode.
Home-scoped roster file — RosterFile.Home: the file lands under this node's account home, chowned to the account; the template sees each node's Account; a machine with no account gets none. Rendering.Accounts carries every node's account for the Host-block User line.
Tested: home-fact placement/owner/skip-no-account, machine account facts, and the ssh-client module composed end-to-end (dir 0700, config into a region of ~/.ssh/config, peer Host blocks with User, self skipped). Behaviour-neutral until a node has an account and ssh-client is assigned. Not deployed.
Pairs with the mesh-catalog ssh-client PR (held until deploy).
The controller half of to-be 29:
- **Account fact** — a node carries its operator account (name + home): migration `0036`, `Node.Account`/`AccountHome`, `Node.Home()` derivation, `inventory.SetAccount`, and a `node account <name> <account> [home]` CLI.
- **Machine facts** — `${machine:account}` / `${machine:account-home}`, and `machineInto` now resolves `${machine:…}` in a resource's **path and owner** (not just content), so a module can place `~/.ssh` at a home it can't hardcode.
- **Home-scoped roster file** — `RosterFile.Home`: the file lands under this node's account home, chowned to the account; the template sees each node's `Account`; a machine with no account gets none. `Rendering.Accounts` carries every node's account for the Host-block `User` line.
Tested: home-fact placement/owner/skip-no-account, machine account facts, and the **ssh-client module composed end-to-end** (dir 0700, config into a region of `~/.ssh/config`, peer Host blocks with `User`, self skipped). Behaviour-neutral until a node has an account and ssh-client is assigned. **Not deployed.**
Pairs with the mesh-catalog `ssh-client` PR (held until deploy).
A node carries its operator account (name + home; migration 0036, Node.Account,
SetAccount, 'node account' CLI). The account and its home are offered as
machine facts ${machine:account} / ${machine:account-home}, and machineInto
now resolves placeholders in a resource's path and owner (not just content), so
a module writes into a person's home naming what it cannot know. A RosterFile
gains Home: the file is placed under the account's home and chowned to it, its
template sees each node's Account, and a machine with no account gets none —
this is how the ssh Host blocks for every node reach a person's ~/.ssh. Roster
carries per-node accounts (Rendering.Accounts). Tested, including ssh-client
composed end-to-end. Not deployed.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The controller half of to-be 29:
0036,Node.Account/AccountHome,Node.Home()derivation,inventory.SetAccount, and anode account <name> <account> [home]CLI.${machine:account}/${machine:account-home}, andmachineIntonow resolves${machine:…}in a resource's path and owner (not just content), so a module can place~/.sshat a home it can't hardcode.RosterFile.Home: the file lands under this node's account home, chowned to the account; the template sees each node'sAccount; a machine with no account gets none.Rendering.Accountscarries every node's account for the Host-blockUserline.Tested: home-fact placement/owner/skip-no-account, machine account facts, and the ssh-client module composed end-to-end (dir 0700, config into a region of
~/.ssh/config, peer Host blocks withUser, self skipped). Behaviour-neutral until a node has an account and ssh-client is assigned. Not deployed.Pairs with the mesh-catalog
ssh-clientPR (held until deploy).A node carries its operator account (name + home; migration 0036, Node.Account, SetAccount, 'node account' CLI). The account and its home are offered as machine facts ${machine:account} / ${machine:account-home}, and machineInto now resolves placeholders in a resource's path and owner (not just content), so a module writes into a person's home naming what it cannot know. A RosterFile gains Home: the file is placed under the account's home and chowned to it, its template sees each node's Account, and a machine with no account gets none — this is how the ssh Host blocks for every node reach a person's ~/.ssh. Roster carries per-node accounts (Rendering.Accounts). Tested, including ssh-client composed end-to-end. Not deployed.