Push-mirror SSH host keys: persist accept-new trust + surface host-key status #625
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub#625
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Follow-up recommended by the #623 review (PR #624): SSH accept-new trust lands on ephemeral disk with no verification surface. Document the choice (done in 13_push_mirror.md), then: persist accepted host keys server-side (bucket sidecar, alongside the mirror config) and surface host-key status (fingerprint, first-accepted-at) in the push-mirror Settings section, so operators can verify/pin instead of trusting every sync. Prod guidance until then: pin known_hosts.
Fixed by #626 (merged): accept-new trust harvested into the bucket secret sidecar (merge, operator pins win, steady-state skips writes, first-accepted-at stamped once) with fingerprint/accepted-at surfaced in the view + Settings (ETag-covered). Review fixed pre-merge: HashKnownHosts=no (salted hashes would defeat dedupe), harvest CAS re-merge loop (concurrent operator PUT no longer clobbered), stamp reset on clear. Verified: pushmirror 95.5%/api 95.4% cover, -race green, stub-git e2e + 1612 web unit green, independent review APPROVE.