Skip to content

feat(ssh): support the server as an encrypted relay participant - #345

Open
theogravity wants to merge 2 commits into
feat/ssh-wizardfrom
feat/ssh-server-relay
Open

theogravity wants to merge 2 commits into
feat/ssh-wizardfrom
feat/ssh-server-relay

Conversation

@theogravity

Copy link
Copy Markdown
Contributor

SSH sessions can now use the server or an enrolled node as either the connecting machine or the source of selected SSH agent keys. Both paths use the same encrypted relay runtime and existing machine launch permissions.

The server has a dedicated persistent relay identity, explicit admin recovery, peer trust management, and backup coverage. Relay cleanup covers shutdown and permission changes; setup-here retains the exact selected keys. Shared pin storage also refuses repeated first-use after quarantining a corrupt trust file.

Stacked on #344.

Validation: full workspace tests, TypeScript checks, lint and license checks; real encrypted relay tests in both directions, selected-key filtering, identity races/recovery, backup roundtrip and socket cleanup. Final node suite: 1,109 passed. Independent review passed with no outstanding findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant