Skip to content

Rename enable-ssh to allow-ssh with cert-authority support - #467

Open
patelspratik wants to merge 1 commit into
pr2-credential-chainfrom
cafornodes
Open

Rename enable-ssh to allow-ssh with cert-authority support#467
patelspratik wants to merge 1 commit into
pr2-credential-chainfrom
cafornodes

Conversation

@patelspratik

@patelspratik patelspratik commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

Rename enable-ssh to allow-ssh. The command now writes a cert-authority,principals="brev:v1:vm::login:" line to authorized_keys using the certificate_authority from the node.

Add disallow-ssh command that removes the cert-authority line.

Register sends sshprovider=certauth label in AddNode. Deregister removes the cert-authority line instead of per-user keys.

@patelspratik
patelspratik force-pushed the cafornodes branch 2 times, most recently from d057349 to a0b3d68 Compare August 29, 2026 01:15
@patelspratik
patelspratik marked this pull request as ready for review August 29, 2026 01:17
@patelspratik
patelspratik requested a review from a team as a code owner August 29, 2026 01:17
@patelspratik patelspratik reopened this Aug 29, 2026
@patelspratik
patelspratik force-pushed the cafornodes branch 2 times, most recently from 8d07d0e to b70231d Compare August 29, 2026 01:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant