From fb4523b2255f638e3a0e3e810a66627853e43ae3 Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Sat, 5 Sep 2026 08:20:23 -0700 Subject: [PATCH] docs: remote-ssh reaches raw IPs now; record the tenant carve-out MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The alias requirement is gone for anything inside 10.0.0.0/8, so the tooling note no longer tells sessions to add an alias first — that instruction was about to send people back to raw ssh, which is what it was written to prevent. Records the SureFire carve-out and why it is host-specific rather than a /24: pfi-pve shares 10.250.250.0/24 with two tenant machines, so a subnet deny would have taken our own hypervisor with it. --- CLAUDE.md | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 6882c75..8327286 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -50,8 +50,18 @@ It deliberately has **no file transfer and no idempotency**; that is elway's hal `allowedHosts` **authoritative** rather than additive — without it, every one of the 18 `Host` entries in `~/.ssh/config` is reachable. Widening that list is a deliberate act; do it in the config file, not by relying on discovery. -- Hosts not in the allowlist return `host_not_allowed`. Hosts reachable only by - raw IP (no `Host` alias) are not reachable at all — add an alias first. +- **Raw IPs work — no alias needed.** Operator ruling 2026-09-05: requiring a host + to be registered before you can poke at it is the opposite of ad-hoc, and the + predictable result is that you use raw `ssh` instead. So `ssh_open` takes an + address inside `allowedNetworks` (`10.0.0.0/8`) and connects as + `defaultUser=infra-ops` with `~/.ssh/infra-ops_ed25519`, `hostKeyPolicy` set to + `accept-new`. Aliases still work and are still required outside those networks. +- ⚠ **`deniedNetworks` carves out the SureFire tenant hosts** — `10.250.150.0/24`, + `10.250.250.115`, `10.250.250.110`. Deny beats allow, so widening the allow list + later cannot re-expose them. They are client property under the hosting + agreement; coordinate before touching, which is a contractual posture and not a + security one. `pfi-pve` (10.250.250.31) is deliberately NOT caught by this — the + denies are host-specific, not a /24 over shared space. **Task visibility via task-board.** If the Claude Code session has the `task-board` plugin enabled (installed from