docs(agent-team): key lives at ~/.ssh/agent-team-apply.pem on the box

The App private key is placed under ~/.ssh (already mode 700) rather than
~/.sea-haven (which holds the synced engineering-handbook). Update the env path,
the secure-copy block, and the rotation/incident-response rm to ~/.ssh.
This commit is contained in:
Adam Moussa 2026-06-24 17:37:07 -04:00
parent 52e8e4bf63
commit 4eb245e83b

View file

@ -108,7 +108,7 @@ never crashes serve):
```
echo 'AGENT_TEAM_GH_APP_ID=4119505' >> ~/secrev.env
echo 'AGENT_TEAM_GH_APP_INSTALLATION_ID=141992144' >> ~/secrev.env
echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.sea-haven/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem
echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.ssh/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem
chmod 600 ~/secrev.env
```
@ -121,10 +121,10 @@ Secure-copy it from the Mac (do NOT commit it; it is not in the repo):
```
# From the Mac (the key lives in ~/Downloads after generation):
scp ~/Downloads/agent-team-apply.*.private-key.pem adam@10.10.60.120:~/.sea-haven/agent-team-apply.pem
# On the box:
chmod 700 ~/.sea-haven && chmod 600 ~/.sea-haven/agent-team-apply.pem
ls -l ~/.sea-haven/agent-team-apply.pem # expect -rw-------
scp ~/Downloads/agent-team-apply.*.private-key.pem secrev:.ssh/agent-team-apply.pem
# On the box (~/.ssh is already mode 700):
chmod 600 ~/.ssh/agent-team-apply.pem
ls -l ~/.ssh/agent-team-apply.pem # expect -rw-------
# Then DELETE the Mac copy (the box now holds the only working copy):
# rm ~/Downloads/agent-team-apply.*.private-key.pem
```
@ -399,7 +399,7 @@ The box holds a write-capable App private key, so it needs its own incident path
# 1. Stop the daemon so no further token mints happen:
sudo systemctl stop agent-team-coordinator.service
# 2. Remove the key + the App env vars from the box (kills the App path -> inert):
rm -f ~/.sea-haven/agent-team-apply.pem
rm -f ~/.ssh/agent-team-apply.pem
sed -i '/AGENT_TEAM_GH_APP_/d' ~/secrev.env
# 3. In GitHub: rotate (generate a new private key, delete the old one) under the
# App's settings, or uninstall the App from the repo to revoke all access.