docs(agent-team): key lives at ~/.ssh/agent-team-apply.pem on the box
The App private key is placed under ~/.ssh (already mode 700) rather than ~/.sea-haven (which holds the synced engineering-handbook). Update the env path, the secure-copy block, and the rotation/incident-response rm to ~/.ssh.
This commit is contained in:
parent
52e8e4bf63
commit
4eb245e83b
1 changed files with 6 additions and 6 deletions
|
|
@ -108,7 +108,7 @@ never crashes serve):
|
||||||
```
|
```
|
||||||
echo 'AGENT_TEAM_GH_APP_ID=4119505' >> ~/secrev.env
|
echo 'AGENT_TEAM_GH_APP_ID=4119505' >> ~/secrev.env
|
||||||
echo 'AGENT_TEAM_GH_APP_INSTALLATION_ID=141992144' >> ~/secrev.env
|
echo 'AGENT_TEAM_GH_APP_INSTALLATION_ID=141992144' >> ~/secrev.env
|
||||||
echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.sea-haven/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem
|
echo 'AGENT_TEAM_GH_APP_PRIVATE_KEY=/home/adam/.ssh/agent-team-apply.pem' >> ~/secrev.env # PATH to the .pem
|
||||||
chmod 600 ~/secrev.env
|
chmod 600 ~/secrev.env
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
@ -121,10 +121,10 @@ Secure-copy it from the Mac (do NOT commit it; it is not in the repo):
|
||||||
|
|
||||||
```
|
```
|
||||||
# From the Mac (the key lives in ~/Downloads after generation):
|
# From the Mac (the key lives in ~/Downloads after generation):
|
||||||
scp ~/Downloads/agent-team-apply.*.private-key.pem adam@10.10.60.120:~/.sea-haven/agent-team-apply.pem
|
scp ~/Downloads/agent-team-apply.*.private-key.pem secrev:.ssh/agent-team-apply.pem
|
||||||
# On the box:
|
# On the box (~/.ssh is already mode 700):
|
||||||
chmod 700 ~/.sea-haven && chmod 600 ~/.sea-haven/agent-team-apply.pem
|
chmod 600 ~/.ssh/agent-team-apply.pem
|
||||||
ls -l ~/.sea-haven/agent-team-apply.pem # expect -rw-------
|
ls -l ~/.ssh/agent-team-apply.pem # expect -rw-------
|
||||||
# Then DELETE the Mac copy (the box now holds the only working copy):
|
# Then DELETE the Mac copy (the box now holds the only working copy):
|
||||||
# rm ~/Downloads/agent-team-apply.*.private-key.pem
|
# rm ~/Downloads/agent-team-apply.*.private-key.pem
|
||||||
```
|
```
|
||||||
|
|
@ -399,7 +399,7 @@ The box holds a write-capable App private key, so it needs its own incident path
|
||||||
# 1. Stop the daemon so no further token mints happen:
|
# 1. Stop the daemon so no further token mints happen:
|
||||||
sudo systemctl stop agent-team-coordinator.service
|
sudo systemctl stop agent-team-coordinator.service
|
||||||
# 2. Remove the key + the App env vars from the box (kills the App path -> inert):
|
# 2. Remove the key + the App env vars from the box (kills the App path -> inert):
|
||||||
rm -f ~/.sea-haven/agent-team-apply.pem
|
rm -f ~/.ssh/agent-team-apply.pem
|
||||||
sed -i '/AGENT_TEAM_GH_APP_/d' ~/secrev.env
|
sed -i '/AGENT_TEAM_GH_APP_/d' ~/secrev.env
|
||||||
# 3. In GitHub: rotate (generate a new private key, delete the old one) under the
|
# 3. In GitHub: rotate (generate a new private key, delete the old one) under the
|
||||||
# App's settings, or uninstall the App from the repo to revoke all access.
|
# App's settings, or uninstall the App from the repo to revoke all access.
|
||||||
|
|
|
||||||
Reference in a new issue