Repository navigation
SSH to any machine, from anywhere (design) - #333
Open
theogravity wants to merge 11 commits into
Open
theogravity wants to merge 11 commits into
theogravity wants to merge 11 commits into
Conversation
theogravity
force-pushed
the
feat/ssh-anywhere
branch
from
October 8, 2026 02:46
0c6325c to
8225c19
Compare
This was referenced Oct 9, 2026
Captures the new line of work: a plain SSH terminal pane to any sshd-only host as the primary product, with two connection modes (stock ProxyJump "Jump", and a plane-blind sealed agent relay "Relay" that authenticates the connecting machine using a key that never leaves its home). The agent-destination boot from the #330 approach becomes an optional upgrade on top. Phased M1 (terminal + jump, no relay) / M2 (the sealed relay, own spec). Design doc only; no implementation. Supersedes the approach on feat/ssh-support (PR #330). Co-Authored-By: Claude <noreply@anthropic.com>
Rewrites the UI section around the real job (pick a destination; origin/key source only as a progressive follow-up; the agent upgrade is a secondary act in the pane). Records that reuse from #330 is code/ideas only and its connect UX is a cautionary example, not a base. Co-Authored-By: Claude <noreply@anthropic.com>
…nabled, fail-closed, audited) Co-Authored-By: Claude <noreply@anthropic.com>
…mitives); spec supersedes SSH-SUPPORT.md Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
…laim, machine-identity gap, grant/pin phasing, SSH_AUTH_SOCK + sharing, gate semantics Co-Authored-By: Claude <noreply@anthropic.com>
…not origin (add B's signature), identity filter from snapshot, saved-hosts store + view-only/direct tests, host-key + mode-naming + success fixes Co-Authored-By: Claude <noreply@anthropic.com>
…(spec 4.3 + plan nodeCanSsh mirrors nodeCanManageFor, no granted param), relay needs a per-machine ES256 signing key, signatures run both ways with the nonce bound, plane-off-transport-path precision, quota/quota-issuer and pin-phrasing tidy-ups
…rs node:<id> (the M2 gap is the node end), plan runs wholly in the worktree, grammar port carries the engines' real import set (errors/results/fixtures included, tests ported not hand-written), kysely three-arg addColumn + 0031-pattern migration test, one ssh-enabled service as the single change site, protocol bump 15->16, audit name node.ssh_enabled.update + docs list, relay pins always strict
…sess-principal peers.json (machine relay gets a separate always-strict store), grammar port gains ssh-frames (the fixtures' type imports, verify-types-visible), Task 2 edges fixed (login-path kept, expandTilde barrel-internal), predicate JSDoc stops promising codes, worktree cd on all commits, plane-side reconcile test added
…s commit, node-side mirror write carries the whole {on, changedAt} wire like writeMaintenance
theogravity
force-pushed
the
feat/ssh-anywhere
branch
from
October 11, 2026 08:48
8225c19 to
1ac7eaf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Design doc only; no implementation. Captures a new line of work for connecting to arbitrary hosts over SSH.
Goal
Open an interactive pane against any host that just runs sshd (node or not, nothing preinstalled), where the SSH identity may live on a different machine than the one that dials the host, with the private key never leaving its home and the control plane never seeing key material or plaintext auth challenges.
Shape
ssh -J B D; key and agent stay home; the pane lives on the key-holder. No new crypto.Branching
Cut from
origin/main, which has none of the #330 ssh-runtime subsystem; only the neutral primitives (config discovery,ssh -Gresolve, the connection-snapshot grammar, the sshd fixture) are re-ported. This supersedes the runtime-on-destination approach on #330, which stays open as a reference for the brokered-session transport M2 may revisit.Spec:
docs/superpowers/specs/2026-10-07-ssh-anywhere-design.md.