Remote access & recovery plane: NetBird-based, operator-owned (implements ADR-002) #59
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Tracking issue for implementing the remote access / recovery plane decided in ADR-002 (
docs/adr/002-remote-access-and-fleet-management.md, on thedevbranch). The full architectural reasoning lives in the ADR; this issue tracks the implementation, to be picked up in the future.Decision recap
Three planes, separated by trust owner:
Key calls:
Implementation tasks
170.75.161.21,deploy/nixos/configuration.nix) with NetBird agent enrollment.authorized_keys— independent of the bitSpire app/runtime, so a crashed box is still reachable.sshdto key-only on deployed boxes; scope password auth to the LAN/first-boot window (relates to #51).OpenAccess/CloseAccesscommand that opens a time-boxed SSH window and logs it as a signed event — on top of the always-available floor and fail-open, never the recovery gate.deploy/nixos/README.md+CLAUDE.mdprovisioning sections.Open questions
ipfield gives way to NetBird enrollment, while hostname / USB serials / touchscreen calibration stay insite.json.Related
docs/adr/002-remote-access-and-fleet-management.md