Add passkey human logins and short-lived SSH certificates #5
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-infra!5
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/passkey-human-login"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Human administration currently depends on manually installed SSH grants. This adds a Keycloak passkey realm, an OIDC-authenticated SSH user certificate issuer, a Linux/Nix
kaiba login/status/logoutclient, and explicit host principal mappings. The initial owner must register two passkeys before receiving SSH authority; certificates bind the immutable issuer/subject and expire within eight hours of issuance.Private credentials remain in runtime storage. Existing owner SSH keys and pilot identities remain separate. Daily snapshots serialize with enrollment changes, encrypt before transfer, and use a restricted receiver. A pinned step-ca patch prevents future-dated certificates from extending the issuance horizon; renew/rekey are denied. Startup waits for Keycloak initialization and verified OIDC discovery, with automatic recovery after restart.
Validation:
kaiba/step login/status/selective logout, and automatic recovery after Keycloak restart.The native test exposed firmware-disabled memory cgroups on Mako. Companion PseudoDesign/nix-pseudo-design#12 fixes this with a kernel parameter; both PRs are merged and deployed, and Mako has rebooted successfully. Effective memory limits, HTTPS, pilot identity/mount preservation and another encrypted backup all pass after reboot, with no OOM events and approximately 895–899 MiB available RAM. Owner hardware-passkey enrollment, the resulting host principal mapping, and an owner-held backup-key recovery drill remain. No production private credentials are included in this change.