Skip to content

SSH to any machine, from anywhere (design) - #333

Open
theogravity wants to merge 11 commits into
mainfrom
feat/ssh-anywhere
Open

theogravity wants to merge 11 commits into
mainfrom
feat/ssh-anywhere

Conversation

@theogravity

Copy link
Copy Markdown
Contributor

Design doc only; no implementation. Captures a new line of work for connecting to arbitrary hosts over SSH.

Goal

Open an interactive pane against any host that just runs sshd (node or not, nothing preinstalled), where the SSH identity may live on a different machine than the one that dials the host, with the private key never leaving its home and the control plane never seeing key material or plaintext auth challenges.

Shape

  • Terminal-first. A plain SSH terminal pane is the primary product; "set up Subshell here" (boot the runtime on the host) is a secondary act on the same connection.
  • Two connection modes, one launcher:
    • Jump - the key-holder connects with stock ssh -J B D; key and agent stay home; the pane lives on the key-holder. No new crypto.
    • Relay - the connecting machine hosts the pane and authenticates through the key-holder's agent over a plane-blind sealed shuttle (encrypted channels carrying the ssh-agent protocol; TOFU origin; no agent forwarding onward to the destination; the relay tears down at handshake completion, so the key is reachable only for seconds).
  • Phasing. M1 = terminal + Jump + discovery/resolve + host-key pinning (no relay). M2 = the sealed agent relay, as its own spec and review.

Branching

Cut from origin/main, which has none of the #330 ssh-runtime subsystem; only the neutral primitives (config discovery, ssh -G resolve, the connection-snapshot grammar, the sshd fixture) are re-ported. This supersedes the runtime-on-destination approach on #330, which stays open as a reference for the brokered-session transport M2 may revisit.

Spec: docs/superpowers/specs/2026-10-07-ssh-anywhere-design.md.

theogravity and others added 11 commits October 11, 2026 01:37
Captures the new line of work: a plain SSH terminal pane to any sshd-only host
as the primary product, with two connection modes (stock ProxyJump "Jump", and a
plane-blind sealed agent relay "Relay" that authenticates the connecting machine
using a key that never leaves its home). The agent-destination boot from the
#330 approach becomes an optional upgrade on top. Phased M1 (terminal + jump, no
relay) / M2 (the sealed relay, own spec). Design doc only; no implementation.

Supersedes the approach on feat/ssh-support (PR #330).

Co-Authored-By: Claude <noreply@anthropic.com>
Rewrites the UI section around the real job (pick a destination; origin/key
source only as a progressive follow-up; the agent upgrade is a secondary act in
the pane). Records that reuse from #330 is code/ideas only and its connect UX is
a cautionary example, not a base.

Co-Authored-By: Claude <noreply@anthropic.com>
…nabled, fail-closed, audited)

Co-Authored-By: Claude <noreply@anthropic.com>
…mitives); spec supersedes SSH-SUPPORT.md

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
…laim, machine-identity gap, grant/pin phasing, SSH_AUTH_SOCK + sharing, gate semantics

Co-Authored-By: Claude <noreply@anthropic.com>
…not origin (add B's signature), identity filter from snapshot, saved-hosts store + view-only/direct tests, host-key + mode-naming + success fixes

Co-Authored-By: Claude <noreply@anthropic.com>
…(spec 4.3 + plan nodeCanSsh mirrors nodeCanManageFor, no granted param), relay needs a per-machine ES256 signing key, signatures run both ways with the nonce bound, plane-off-transport-path precision, quota/quota-issuer and pin-phrasing tidy-ups
…rs node:<id> (the M2 gap is the node end), plan runs wholly in the worktree, grammar port carries the engines' real import set (errors/results/fixtures included, tests ported not hand-written), kysely three-arg addColumn + 0031-pattern migration test, one ssh-enabled service as the single change site, protocol bump 15->16, audit name node.ssh_enabled.update + docs list, relay pins always strict
…sess-principal peers.json (machine relay gets a separate always-strict store), grammar port gains ssh-frames (the fixtures' type imports, verify-types-visible), Task 2 edges fixed (login-path kept, expandTilde barrel-internal), predicate JSDoc stops promising codes, worktree cd on all commits, plane-side reconcile test added
…s commit, node-side mirror write carries the whole {on, changedAt} wire like writeMaintenance
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant