Skip to content

rename enable-ssh to allow-ssh and use SSH Certs instead of keys - #460

Draft
patelspratik wants to merge 1 commit into
mainfrom
cafornodes
Draft

rename enable-ssh to allow-ssh and use SSH Certs instead of keys#460
patelspratik wants to merge 1 commit into
mainfrom
cafornodes

Conversation

@patelspratik

@patelspratik patelspratik commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

@patelspratik
patelspratik force-pushed the cafornodes branch 2 times, most recently from 35f8f10 to a1ba25c Compare August 27, 2026 15:38
@patelspratik patelspratik changed the title Cafornodes rename enable-ssh to allow-ssh and use SSH Certs instead of keys Aug 27, 2026
@patelspratik
patelspratik force-pushed the cafornodes branch 2 times, most recently from 3d26196 to dc366d0 Compare August 27, 2026 19:38
Rename enable-ssh to allow-ssh. The command now writes a
cert-authority,principals="brev:v1:vm:<nodeID>:login:<user>" <CA key>
line to authorized_keys using the certificate_authority from the node.

Add disallow-ssh command that removes the cert-authority line.

Register sends sshprovider=certauth label in AddNode. Deregister
removes the cert-authority line instead of per-user keys.

CLI go.mod uses a local replace for the proto module until the BSR
publishes the certificate_authority field.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant