diff --git a/CLAUDE.md b/CLAUDE.md index 6882c75..8327286 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -50,8 +50,18 @@ It deliberately has **no file transfer and no idempotency**; that is elway's hal `allowedHosts` **authoritative** rather than additive — without it, every one of the 18 `Host` entries in `~/.ssh/config` is reachable. Widening that list is a deliberate act; do it in the config file, not by relying on discovery. -- Hosts not in the allowlist return `host_not_allowed`. Hosts reachable only by - raw IP (no `Host` alias) are not reachable at all — add an alias first. +- **Raw IPs work — no alias needed.** Operator ruling 2026-09-05: requiring a host + to be registered before you can poke at it is the opposite of ad-hoc, and the + predictable result is that you use raw `ssh` instead. So `ssh_open` takes an + address inside `allowedNetworks` (`10.0.0.0/8`) and connects as + `defaultUser=infra-ops` with `~/.ssh/infra-ops_ed25519`, `hostKeyPolicy` set to + `accept-new`. Aliases still work and are still required outside those networks. +- ⚠ **`deniedNetworks` carves out the SureFire tenant hosts** — `10.250.150.0/24`, + `10.250.250.115`, `10.250.250.110`. Deny beats allow, so widening the allow list + later cannot re-expose them. They are client property under the hosting + agreement; coordinate before touching, which is a contractual posture and not a + security one. `pfi-pve` (10.250.250.31) is deliberately NOT caught by this — the + denies are host-specific, not a /24 over shared space. **Task visibility via task-board.** If the Claude Code session has the `task-board` plugin enabled (installed from