diff --git a/agent-team/DEPLOY-R720.md b/agent-team/DEPLOY-R720.md index cfdf480..8521736 100644 --- a/agent-team/DEPLOY-R720.md +++ b/agent-team/DEPLOY-R720.md @@ -108,7 +108,7 @@ never crashes serve): ``` echo 'AGENT_TEAM_GH_APP_ID=4119505' >> ~/secrev.env echo 'AGENT_TEAM_GH_APP_INSTALLATION_ID=141992144' >> ~/secrev.env -echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.sea-haven/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem +echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.ssh/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem chmod 600 ~/secrev.env ``` @@ -121,10 +121,10 @@ Secure-copy it from the Mac (do NOT commit it; it is not in the repo): ``` # From the Mac (the key lives in ~/Downloads after generation): -scp ~/Downloads/agent-team-apply.*.private-key.pem adam@10.10.60.120:~/.sea-haven/agent-team-apply.pem -# On the box: -chmod 700 ~/.sea-haven && chmod 600 ~/.sea-haven/agent-team-apply.pem -ls -l ~/.sea-haven/agent-team-apply.pem # expect -rw------- +scp ~/Downloads/agent-team-apply.*.private-key.pem secrev:.ssh/agent-team-apply.pem +# On the box (~/.ssh is already mode 700): +chmod 600 ~/.ssh/agent-team-apply.pem +ls -l ~/.ssh/agent-team-apply.pem # expect -rw------- # Then DELETE the Mac copy (the box now holds the only working copy): # rm ~/Downloads/agent-team-apply.*.private-key.pem ``` @@ -399,7 +399,7 @@ The box holds a write-capable App private key, so it needs its own incident path # 1. Stop the daemon so no further token mints happen: sudo systemctl stop agent-team-coordinator.service # 2. Remove the key + the App env vars from the box (kills the App path -> inert): -rm -f ~/.sea-haven/agent-team-apply.pem +rm -f ~/.ssh/agent-team-apply.pem sed -i '/AGENT_TEAM_GH_APP_/d' ~/secrev.env # 3. In GitHub: rotate (generate a new private key, delete the old one) under the # App's settings, or uninstall the App from the repo to revoke all access.