Page MenuHomePhabricator

Add a query/policy layer on top of SSH keys for Almanac
ClosedPublic

Authored by epriestley on Nov 5 2014, 8:14 PM.
Tags
None
Referenced Files
F18817234: D10790.id25912.diff
Tue, Oct 21, 1:42 PM
F18669519: D10790.id25889.diff
Wed, Sep 24, 8:50 PM
F18627332: D10790.diff
Sep 16 2025, 3:44 AM
F18627284: D10790.diff
Sep 16 2025, 3:40 AM
F18619321: D10790.diff
Sep 15 2025, 2:14 AM
F18581934: D10790.diff
Sep 11 2025, 7:09 AM
F18504360: D10790.id.diff
Sep 4 2025, 11:45 PM
F18416216: D10790.id.diff
Aug 30 2025, 10:28 AM
Subscribers

Details

Summary

Ref T5833. Currently, SSH keys are associated only with users, and are a bit un-modern. I want to let Almanac Devices have SSH keys so devices in a cluster can identify to one another.

For example, with hosted installs, initialization will go something like this:

  • A request comes in for company.phacility.com.
  • A SiteSource (from D10787) makes a Conduit call to Almanac on the master install to check if company is a valid install and pull config if it is.
  • This call can be signed with an SSH key which identifies a trusted Almanac Device.

In the cluster case, a web host can make an authenticated call to a repository host with similar key signing.

To move toward this, put a proper Query class on top of SSH key access (this diff). In following diffs, I'll:

  • Rename userPHID to objectPHID.
  • Move this to the auth database.
  • Provide UI for device/key association.

An alternative approach would be to build some kind of special token layer in Conduit, but I think that would be a lot harder to manage in the hosting case. This gives us a more direct attack on trusting requests from machines and recognizing machines as first (well, sort of second-class) actors without needing things like fake user accounts.

Test Plan
  • Added and removed SSH keys.
  • Added and removed SSH keys from a bot account.
  • Tried to edit an unonwned SSH key (denied).
  • Ran bin/ssh-auth, got sensible output.
  • Ran bin/ssh-auth-key, got sensible output.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Add a query/policy layer on top of SSH keys for Almanac.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Nov 5 2014, 10:05 PM
This revision was automatically updated to reflect the committed changes.