Skip to content

feat: allow officina-ci to SSH to officina-instance hosts#361

Merged
noahwhite merged 1 commit intodevelopfrom
feature/GHO-off64-tailscale-acl-officina-ci
Apr 5, 2026
Merged

feat: allow officina-ci to SSH to officina-instance hosts#361
noahwhite merged 1 commit intodevelopfrom
feature/GHO-off64-tailscale-acl-officina-ci

Conversation

@noahwhite
Copy link
Copy Markdown
Owner

@noahwhite noahwhite commented Apr 5, 2026

Summary

  • Add Tailscale ACL grant: tag:officina-citag:officina-instance on port 22
  • Add Tailscale SSH rule: tag:officina-citag:officina-instance as root (action: accept)

Required for the officina provision-host-secrets workflow to deposit tokens and trigger the reconciler on host instances via tailscale ssh.

Test plan

  • tofu plan shows ACL update
  • After apply, retrigger officina manual workflow — verify tailscale ssh connects to ghost-shared-01

Add Tailscale ACL grant and SSH rule so tag:officina-ci can reach
tag:officina-instance on port 22 as root. Required for the officina
provision-host-secrets workflow to deposit tokens and trigger the
reconciler via tailscale ssh.
@noahwhite noahwhite self-assigned this Apr 5, 2026
@noahwhite noahwhite merged commit 3eeb402 into develop Apr 5, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant