From 012fecef5ed25fdf5c83a82930c503e418e96a1a Mon Sep 17 00:00:00 2001 From: Padreug Date: Tue, 22 Sep 2026 20:14:46 +0200 Subject: [PATCH] fix(deploy): trust the Forgejo host key so auto-upgrade can fetch system.autoUpgrade fetches the flake over ssh as root. A machine whose root has never connected by hand has no known_hosts entry, so the run dies at 'Host key verification failed' before it even reaches authentication. batm3 did exactly that, silently, from its 2026-08-06 install until 09-22: six weeks on its install generation while a unit nobody was watching reported failure every night. sintra only ever worked because a human had ssh'd as root once and accepted the key. Declaring the key means a freshly flashed ATM updates from first boot with no manual step. Verified against the key sintra's root already trusts. Refs #98 Co-Authored-By: Claude Fable 5.1 --- deploy/nixos/configuration.nix | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/deploy/nixos/configuration.nix b/deploy/nixos/configuration.nix index 2306f5a..330421c 100644 --- a/deploy/nixos/configuration.nix +++ b/deploy/nixos/configuration.nix @@ -159,6 +159,18 @@ # Auto-updates (optional - disabled by default for stability) # system.autoUpgrade.enable = false; + # Trust the Forgejo host key up front. system.autoUpgrade fetches the flake + # over ssh AS ROOT, and a machine whose root has never connected by hand has + # no known_hosts entry, so every nightly run dies at + # "Host key verification failed" before it reaches authentication. batm3 did + # exactly that, silently, from its 2026-08-06 install until 09-22 (#98): it + # sat on its install generation for six weeks while reporting a failed unit + # nobody was watching. sintra only ever worked because a human had ssh'd as + # root once and accepted the key. Declaring it means a freshly flashed ATM + # can update from first boot with no manual step. + programs.ssh.knownHosts."git.atitlan.io".publicKey = + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMlo3f05o4+bk0+8x2VG91o9GubshOb46HmBPvND9pJx"; + # pragma: allowlist secret # Ensure WireGuard private key directory exists with correct permissions system.activationScripts.wireguard-key = ''