feat(mother): add mother-sync-hive-keys — rebuild authorized_keys from vault #140
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "mother-sync-hive-keys"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Mother side of the vault-mediated hive key exchange. Pulls the
hive-pubkey-*items agents publish to Vaultwarden and rebuilds the colibri user'sauthorized_keys, each entry restricted to the MCP command (command="colibri-mcp",restrict,no-pty,no-*-forwarding).authorized_keysuntouched.0600.PROVIDER_ENV/COLIBRI_HOME/COLIBRI_USER/MCP_COMMAND— mother = osa for now; a dedicated host is just a config change.bitwarden-cli-vaultskill patterns.Verified:
sh -nclean; parse/rebuild core tested (filters non-key items, strips key comments, applies the restriction wrapper). Needs Hermes hardware validation on osa (bw + thehive-pubkeysitems + sshd).🤖 Generated with Claude Code