Repository navigation
fix: include Hero destination in canonical known-host source - #75
Conversation
OpenTofu TestOpenTofu test passed. View run output |
OpenTofu PlanOpenTofu plan passed. View run outputOpenTofu will perform the following actions:
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
id = "hero-host-config:HERO_HOST_CONFIG_SSH_KNOWN_HOSTS"
~ plaintext_value = (sensitive value)
# (7 unchanged attributes hidden)
}
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
id = "tfroot-libvirt:SSH_KNOWN_HOSTS"
~ plaintext_value = (sensitive value)
# (8 unchanged attributes hidden)
}
Plan: 0 to add, 2 to change, 0 to destroy.
OpenTofu will perform the following actions:
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
id = "hero-host-config:HERO_HOST_CONFIG_SSH_KNOWN_HOSTS"
~ plaintext_value = (sensitive value)
# (7 unchanged attributes hidden)
}
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
id = "tfroot-libvirt:SSH_KNOWN_HOSTS"
~ plaintext_value = (sensitive value)
# (8 unchanged attributes hidden)
}
Plan: 0 to add, 2 to change, 0 to destroy. |
|
Owner explicitly instructed “merge and proceed” on 2026-10-05 after being informed of passing final-head CI (0 add / 2 change / 0 destroy) and the unresolved redaction of exact resource identities. This supersedes the draft-only authorization: proceed with merge at e401c37, the existing automatic main apply, and source/consumer check-only validation. The owner accepts the encrypted-content review and exact-resource evidence limitations; these are waived, not independently resolved. No host/firewall apply, key rotation, libvirt source retirement, or retrieval of secret material is authorized. Current main remains21a0eca21db3525266a4f6cf25f666e73b748243 and final-head checks pass. |
|
Delivery follow-up: merged at Fresh Hero check-only run passed known-host preflight and WARP enrollment and reached remote Ansible tasks with strict host checking retained. It subsequently failed at the Node Exporter service task because the requested service was not found. Package installation reported a proposed change in check mode; it did not install the package. Cleanup succeeded. The original destination-matching failure is resolved for this path, but full playbook/Node Exporter readiness is not established. No host/firewall apply or libvirt source retirement was performed. No claim of byte-for-byte secret equality or separate libvirt validation. |
Summary
Owner-authored SOPS correction to the canonical
ssh_known_hostsfield insecrets/secrets.yaml. Owner reports the former entry covered the hostname while the consumer uses an IP destination; intended correction preserves hostname coverage and adds the destination alias for the same trusted key. No key material or destination is reproduced here.Commit
7547dd85872c8eb8e9883914dab01aa11257daf5changes onlysecrets/secrets.yaml(4 additions, 4 deletions by metadata). The agent has not retrieved ciphertext or decrypted content.Fixes: N/A — follow-up to source diagnostic PR #72.
Type of change
Validation
e401c379d4b7265534aa3276ebd08d949c815b95. Apply and real source diagnostic skipped on PR.Explicit owner waiver, 2026-10-05: owner approved opening this draft using their SOPS-edit attestation with the encrypted-content review limitation recorded. Adversarial, security, and delivery reviews remain evidence-limited/HOLD rather than code-review-approved; the delivery reviewer rated missing complete-change evidence High. The waiver permits draft creation and CI evaluation only. It does not verify encryption, recipient preservation, plaintext correctness, or absence of other field changes, and does not authorize merge, apply, or dispatch. Do not retrieve protected content to satisfy review.
The branch was created before current main
21a0eca21db3525266a4f6cf25f666e73b748243. The branch was updated via GitHub to heade401c379d4b7265534aa3276ebd08d949c815b95before accepting final CI: the reusable plan workflow checks out PR HEAD, not the merge ref. Ignore initial stale-head plans as approval evidence.Expected scope: updates to the two existing known-host Actions secrets, zero additions/deletions and no unrelated changes. This is an expectation, not a verified plan. Record any safe-summary redaction limits; never fetch raw sensitive plans.
Impact and rollout
Canonical producer: tfroot-github
secrets/secrets.yaml->secrets.tfSOPS lookupssh_known_hosts->gh-secrets.tfgithub_actions_secret.secrets. Existing recipients arehero-host-config/HERO_HOST_CONFIG_SSH_KNOWN_HOSTSandtfroot-libvirt/SSH_KNOWN_HOSTS. Mapping and resource code are unchanged by this correction. Distribution is not atomic, and successful apply alone does not prove a particular resource changed or successful downstream SSH.Authored/pushed: owner correction complete. PR test/plan and synthetic tests: automatic, passed. Branch update: completed. Merge/main environment-scoped apply: separate confirmation required; merging triggers the existing main workflow. Source diagnostic and fresh Hero check-only dispatch: separate manual confirmation gates. Source matching, distribution, strict host verification, and functional behavior remain distinct. No host/firewall mutation, private-key rotation, libvirt source retirement, image/chart publication, or GitOps change is included. Existing shared-workflow and runner selections are unchanged.
Rollback before delivery: close the PR. After delivery: owner restores an approved encrypted source through a reviewed PR and separately approved apply. Do not restore untrusted host keys or disable strict checking.
Safety and secrets
Owner authored the encrypted change. AI assistance is limited to metadata/source-contract review, PR preparation, and CI monitoring. No merge or runtime action is authorized by this draft.
Final-head CI evidence
Synthetic tests and OpenTofu test/plan passed. Redacted plan summary: 0 to add, 2 to change, 0 to destroy. Counts match the intended scope, but the redacted summary does not expose the two expected resource identities, so exact resource scope is not independently established. No raw plan or encrypted-file contents were retrieved. Owner review of exact non-sensitive resource identities remains a merge gate. No merge, apply, or dispatch performed; draft and review waiver limitations remain in force.