docs: remote-ssh reaches raw IPs now; record the tenant carve-out
The alias requirement is gone for anything inside 10.0.0.0/8, so the tooling note no longer tells sessions to add an alias first — that instruction was about to send people back to raw ssh, which is what it was written to prevent. Records the SureFire carve-out and why it is host-specific rather than a /24: pfi-pve shares 10.250.250.0/24 with two tenant machines, so a subnet deny would have taken our own hypervisor with it.
This commit is contained in:
@@ -50,8 +50,18 @@ It deliberately has **no file transfer and no idempotency**; that is elway's hal
|
||||
`allowedHosts` **authoritative** rather than additive — without it, every one of
|
||||
the 18 `Host` entries in `~/.ssh/config` is reachable. Widening that list is a
|
||||
deliberate act; do it in the config file, not by relying on discovery.
|
||||
- Hosts not in the allowlist return `host_not_allowed`. Hosts reachable only by
|
||||
raw IP (no `Host` alias) are not reachable at all — add an alias first.
|
||||
- **Raw IPs work — no alias needed.** Operator ruling 2026-09-05: requiring a host
|
||||
to be registered before you can poke at it is the opposite of ad-hoc, and the
|
||||
predictable result is that you use raw `ssh` instead. So `ssh_open` takes an
|
||||
address inside `allowedNetworks` (`10.0.0.0/8`) and connects as
|
||||
`defaultUser=infra-ops` with `~/.ssh/infra-ops_ed25519`, `hostKeyPolicy` set to
|
||||
`accept-new`. Aliases still work and are still required outside those networks.
|
||||
- ⚠ **`deniedNetworks` carves out the SureFire tenant hosts** — `10.250.150.0/24`,
|
||||
`10.250.250.115`, `10.250.250.110`. Deny beats allow, so widening the allow list
|
||||
later cannot re-expose them. They are client property under the hosting
|
||||
agreement; coordinate before touching, which is a contractual posture and not a
|
||||
security one. `pfi-pve` (10.250.250.31) is deliberately NOT caught by this — the
|
||||
denies are host-specific, not a /24 over shared space.
|
||||
|
||||
**Task visibility via task-board.** If the Claude Code session has
|
||||
the `task-board` plugin enabled (installed from
|
||||
|
||||
Reference in New Issue
Block a user