Skip to content

fix(OFF-64): use core user for officina-ci SSH#362

Merged
noahwhite merged 1 commit intodevelopfrom
feature/OFF-64-ci-ssh-core
Apr 5, 2026
Merged

fix(OFF-64): use core user for officina-ci SSH#362
noahwhite merged 1 commit intodevelopfrom
feature/OFF-64-ci-ssh-core

Conversation

@noahwhite
Copy link
Copy Markdown
Owner

Summary

  • Changes Tailscale SSH ACL rule for tag:officina-citag:officina-instance from root to core
  • CI workflows will use core@ with sudo for privileged operations instead of direct root access
  • Companion to officina-pub/officina#180 which updates the workflow commands

Test plan

  • ACL applied via deploy
  • Manual provision-host-secrets workflow succeeds with core + sudo

Least privilege: CI connects as core with sudo instead of root.
Provides audit trail for privileged operations in journald.
@noahwhite noahwhite self-assigned this Apr 5, 2026
@noahwhite noahwhite merged commit 0be4972 into develop Apr 5, 2026
6 checks passed
@noahwhite noahwhite deleted the feature/OFF-64-ci-ssh-core branch April 5, 2026 02:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant