docs(agent-team): key lives at ~/.ssh/agent-team-apply.pem on the box
The App private key is placed under ~/.ssh (already mode 700) rather than ~/.sea-haven (which holds the synced engineering-handbook). Update the env path, the secure-copy block, and the rotation/incident-response rm to ~/.ssh.
This commit is contained in:
parent
52e8e4bf63
commit
4eb245e83b
1 changed files with 6 additions and 6 deletions
|
|
@ -108,7 +108,7 @@ never crashes serve):
|
|||
```
|
||||
echo 'AGENT_TEAM_GH_APP_ID=4119505' >> ~/secrev.env
|
||||
echo 'AGENT_TEAM_GH_APP_INSTALLATION_ID=141992144' >> ~/secrev.env
|
||||
echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.sea-haven/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem
|
||||
echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.ssh/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem
|
||||
chmod 600 ~/secrev.env
|
||||
```
|
||||
|
||||
|
|
@ -121,10 +121,10 @@ Secure-copy it from the Mac (do NOT commit it; it is not in the repo):
|
|||
|
||||
```
|
||||
# From the Mac (the key lives in ~/Downloads after generation):
|
||||
scp ~/Downloads/agent-team-apply.*.private-key.pem adam@10.10.60.120:~/.sea-haven/agent-team-apply.pem
|
||||
# On the box:
|
||||
chmod 700 ~/.sea-haven && chmod 600 ~/.sea-haven/agent-team-apply.pem
|
||||
ls -l ~/.sea-haven/agent-team-apply.pem # expect -rw-------
|
||||
scp ~/Downloads/agent-team-apply.*.private-key.pem secrev:.ssh/agent-team-apply.pem
|
||||
# On the box (~/.ssh is already mode 700):
|
||||
chmod 600 ~/.ssh/agent-team-apply.pem
|
||||
ls -l ~/.ssh/agent-team-apply.pem # expect -rw-------
|
||||
# Then DELETE the Mac copy (the box now holds the only working copy):
|
||||
# rm ~/Downloads/agent-team-apply.*.private-key.pem
|
||||
```
|
||||
|
|
@ -399,7 +399,7 @@ The box holds a write-capable App private key, so it needs its own incident path
|
|||
# 1. Stop the daemon so no further token mints happen:
|
||||
sudo systemctl stop agent-team-coordinator.service
|
||||
# 2. Remove the key + the App env vars from the box (kills the App path -> inert):
|
||||
rm -f ~/.sea-haven/agent-team-apply.pem
|
||||
rm -f ~/.ssh/agent-team-apply.pem
|
||||
sed -i '/AGENT_TEAM_GH_APP_/d' ~/secrev.env
|
||||
# 3. In GitHub: rotate (generate a new private key, delete the old one) under the
|
||||
# App's settings, or uninstall the App from the repo to revoke all access.
|
||||
|
|
|
|||
Reference in a new issue