Archived
feat(secrets): add push-host-keys.sh; integrate into sync/recover scripts
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m18s
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m18s
New script: scripts/secrets/push-host-keys.sh - Pushes newly-generated SSH host keys from host-keys/ to already-running NixOS hosts after sync-host-keys.sh --regenerate-all-keys. - Before pushing any key, checks that .sops.yaml and secrets/*.yaml are committed and pushed to the remote Gitea flake (hosts rebuild from there, so recipient changes must land first); offers to auto-commit/push if not. - Reads /etc/flake-target from each host to confirm which key to install, handling the case where multiple flake targets share a hostname. - Deduplicates by hostname in --all mode; skips hand-registered targets that have no host-keys/ entry. - --dry-run, --skip-git-check, SSH_USER override (default: nixos). sync-host-keys.sh --regenerate-all-keys: - Updated pre-confirmation warning to distinguish already-running hosts (need push-host-keys.sh) from not-yet-deployed hosts (need installer image rebuild). - Added next-steps block after regeneration completes pointing to push-host-keys.sh --all. recover-hosts.sh: - Header and SSH host key mismatch warn now cross-reference push-host-keys.sh as the proactive (pre-drift) alternative. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -12,6 +12,9 @@
|
||||
# Fixes applied automatically (then prompts before rebuilding):
|
||||
# 1. SSH host key drift — live key no longer matches host-keys/<target>_ssh_host_ed25519_key
|
||||
# Fix: scp the registered key back and restore it (needs sudo once per host).
|
||||
# To push new keys proactively (before drift, e.g. right after
|
||||
# sync-host-keys.sh --regenerate-all-keys), use instead:
|
||||
# scripts/secrets/push-host-keys.sh --all
|
||||
# 2. Stale/invalid GitHub access token — the rendered nix-github-token.conf has
|
||||
# a token GitHub rejects (401), blocking any rebuild that fetches disko or
|
||||
# other public GitHub flake inputs.
|
||||
@@ -131,7 +134,7 @@ for host in "${HOSTNAMES[@]}"; do
|
||||
if [ "$live" = "$want" ]; then
|
||||
info "SSH host key OK"
|
||||
else
|
||||
warn "SSH host key MISMATCH (live ≠ host-keys/)"
|
||||
warn "SSH host key MISMATCH (live ≠ host-keys/) -- use push-host-keys.sh proactively next time"
|
||||
echo " live: $live"
|
||||
echo " registered: $want"
|
||||
host_broken=true
|
||||
|
||||
Reference in New Issue
Block a user