Skip to content

fix: include Hero destination in canonical known-host source - #75

Merged
xnoto merged 2 commits into
mainfrom
fix/hero-known-host-source-entry
Oct 5, 2026
Merged

xnoto merged 2 commits into
mainfrom
fix/hero-known-host-source-entry

Conversation

@xnoto

@xnoto xnoto commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Owner-authored SOPS correction to the canonical ssh_known_hosts field in secrets/secrets.yaml. Owner reports the former entry covered the hostname while the consumer uses an IP destination; intended correction preserves hostname coverage and adds the destination alias for the same trusted key. No key material or destination is reproduced here.

Commit 7547dd85872c8eb8e9883914dab01aa11257daf5 changes only secrets/secrets.yaml (4 additions, 4 deletions by metadata). The agent has not retrieved ciphertext or decrypted content.

Fixes: N/A — follow-up to source diagnostic PR #72.

Type of change

  • Bug fix
  • Feature / enhancement
  • Documentation
  • Infrastructure (OpenTofu root or module)
  • GitOps desired state (manifests, kustomize, charts, SOPS/KSOPS secrets)
  • Container image
  • CI / reusable workflow
  • Refactor / cleanup
  • Breaking change

Validation

  • Final-head synthetic tests and OpenTofu test/plan passed at e401c379d4b7265534aa3276ebd08d949c815b95. Apply and real source diagnostic skipped on PR.
  • Generated or centrally distributed files were regenerated by their owning automation, not hand-edited — no generated files changed.

Explicit owner waiver, 2026-10-05: owner approved opening this draft using their SOPS-edit attestation with the encrypted-content review limitation recorded. Adversarial, security, and delivery reviews remain evidence-limited/HOLD rather than code-review-approved; the delivery reviewer rated missing complete-change evidence High. The waiver permits draft creation and CI evaluation only. It does not verify encryption, recipient preservation, plaintext correctness, or absence of other field changes, and does not authorize merge, apply, or dispatch. Do not retrieve protected content to satisfy review.

The branch was created before current main 21a0eca21db3525266a4f6cf25f666e73b748243. The branch was updated via GitHub to head e401c379d4b7265534aa3276ebd08d949c815b95 before accepting final CI: the reusable plan workflow checks out PR HEAD, not the merge ref. Ignore initial stale-head plans as approval evidence.

Expected scope: updates to the two existing known-host Actions secrets, zero additions/deletions and no unrelated changes. This is an expectation, not a verified plan. Record any safe-summary redaction limits; never fetch raw sensitive plans.

Impact and rollout

Canonical producer: tfroot-github secrets/secrets.yaml -> secrets.tf SOPS lookup ssh_known_hosts -> gh-secrets.tf github_actions_secret.secrets. Existing recipients are hero-host-config/HERO_HOST_CONFIG_SSH_KNOWN_HOSTS and tfroot-libvirt/SSH_KNOWN_HOSTS. Mapping and resource code are unchanged by this correction. Distribution is not atomic, and successful apply alone does not prove a particular resource changed or successful downstream SSH.

Authored/pushed: owner correction complete. PR test/plan and synthetic tests: automatic, passed. Branch update: completed. Merge/main environment-scoped apply: separate confirmation required; merging triggers the existing main workflow. Source diagnostic and fresh Hero check-only dispatch: separate manual confirmation gates. Source matching, distribution, strict host verification, and functional behavior remain distinct. No host/firewall mutation, private-key rotation, libvirt source retirement, image/chart publication, or GitOps change is included. Existing shared-workflow and runner selections are unchanged.

Rollback before delivery: close the PR. After delivery: owner restores an approved encrypted source through a reviewed PR and separately approved apply. Do not restore untrusted host keys or disable strict checking.

Safety and secrets

  • Contains no plaintext secrets, decrypted SOPS values, state files, kubeconfigs, tokens, or private endpoints — encrypted source is owner-attested; contents were not independently inspected by the agent. PR prose contains none.
  • No local OpenTofu init/plan/apply/destroy/import/state operations were run or claimed — plans come from pull-request checks.
  • Breaking or irreversible effects are described above with rollback notes.

Owner authored the encrypted change. AI assistance is limited to metadata/source-contract review, PR preparation, and CI monitoring. No merge or runtime action is authorized by this draft.

Final-head CI evidence

Synthetic tests and OpenTofu test/plan passed. Redacted plan summary: 0 to add, 2 to change, 0 to destroy. Counts match the intended scope, but the redacted summary does not expose the two expected resource identities, so exact resource scope is not independently established. No raw plan or encrypted-file contents were retrieved. Owner review of exact non-sensitive resource identities remains a merge gate. No merge, apply, or dispatch performed; draft and review waiver limitations remain in force.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

OpenTofu Test

OpenTofu test passed.

View the workflow run.

View run output
Terraform validate.......................................................Passed
Terraform validate with tflint...........................................Passed
Checkov..................................................................Passed
Terraform fmt............................................................Passed
Terraform docs...........................................................Passed
Detect hardcoded secrets.................................................Passed
check for case conflicts.................................................Passed
check for merge conflicts................................................Passed
check for broken symlinks............................(no files to check)Skipped
check vcs permalinks.....................................................Passed
detect destroyed symlinks................................................Passed
detect private key.......................................................Passed
fix end of files.........................................................Passed
mixed line ending........................................................Passed
trim trailing whitespace.................................................Passed
don't commit to branch..................................................Skipped
check for added large files..............................................Passed

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

OpenTofu Plan

OpenTofu plan passed.

View the workflow run.

View run output
OpenTofu will perform the following actions:

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
        id                = "hero-host-config:HERO_HOST_CONFIG_SSH_KNOWN_HOSTS"
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
        id                = "tfroot-libvirt:SSH_KNOWN_HOSTS"
      ~ plaintext_value   = (sensitive value)
        # (8 unchanged attributes hidden)
    }

Plan: 0 to add, 2 to change, 0 to destroy.
OpenTofu will perform the following actions:

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
        id                = "hero-host-config:HERO_HOST_CONFIG_SSH_KNOWN_HOSTS"
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
        id                = "tfroot-libvirt:SSH_KNOWN_HOSTS"
      ~ plaintext_value   = (sensitive value)
        # (8 unchanged attributes hidden)
    }

Plan: 0 to add, 2 to change, 0 to destroy.

@xnoto

xnoto commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Owner explicitly instructed “merge and proceed” on 2026-10-05 after being informed of passing final-head CI (0 add / 2 change / 0 destroy) and the unresolved redaction of exact resource identities. This supersedes the draft-only authorization: proceed with merge at e401c37, the existing automatic main apply, and source/consumer check-only validation. The owner accepts the encrypted-content review and exact-resource evidence limitations; these are waived, not independently resolved. No host/firewall apply, key rotation, libvirt source retirement, or retrieval of secret material is authorized. Current main remains21a0eca21db3525266a4f6cf25f666e73b748243 and final-head checks pass.

@xnoto
xnoto marked this pull request as ready for review October 5, 2026 00:30
@xnoto
xnoto requested a review from a team as a code owner October 5, 2026 00:30
@xnoto
xnoto merged commit 2a4aae0 into main Oct 5, 2026
5 checks passed
@xnoto
xnoto deleted the fix/hero-known-host-source-entry branch October 5, 2026 00:30
@xnoto

xnoto commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Delivery follow-up: merged at 2a4aae0ef3e092b5d091706b0aef29c21ca12f30. Main apply succeeded; source diagnostic returned match-found, with cleanup successful.

Fresh Hero check-only run passed known-host preflight and WARP enrollment and reached remote Ansible tasks with strict host checking retained. It subsequently failed at the Node Exporter service task because the requested service was not found. Package installation reported a proposed change in check mode; it did not install the package. Cleanup succeeded. The original destination-matching failure is resolved for this path, but full playbook/Node Exporter readiness is not established. No host/firewall apply or libvirt source retirement was performed. No claim of byte-for-byte secret equality or separate libvirt validation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant