Revisions and Commits
Revisions and Commits
Restricted Diffusion Commit | |
Restricted Diffusion Commit |
Status | Assigned | Task | ||
---|---|---|---|---|
Resolved | epriestley | T8210 Phacility Cluster: Bastion host stopped responding | ||
Resolved | epriestley | T8206 Make authorize-user part of bastion deployment |
Event Timeline
Comment Actions
Deploying a bastion host now synchronizes account, key and sudoer state automatically.
The bin/remote authorize command is now obsolete.
I've updated the documentation.
(As a bonus, it looks like I fixed that prompting for new config file stuff, too.)
Comment Actions
I also realigned the use of DNS. We now use:
- bastion.phacility.net: Internal service. TTL 30s.
- bastion-external.phacility.net: External service. TTL 30s.
This is more flexible and consistent than the old approach, and has a 90% shorter TTL.