feat(box): passkey fetch, agent key-approval flow, unified lookups, tmux agent UX
- box passkey [show|fetch] (+ muse passkey): documents VM-only passkey (/srv/box/passkey.txt, fallback /etc/netvm/passkey.txt on 34.139.37.135), probes VM over SSH with graceful fallback; --json supported. No secrets on bl. - approvals: request_key_approval / check_node_key_request; KEY_APPROVAL status surfaced in `box approvals check`; allow/deny resolve + audit to box-ctl.jsonl; never auto-approved. New `box approvals request-key <node> --reason`. - box lookup (summary|fleet|threads|unread|approvals|key|docs) and docs-lookup engine with lookup_internal/ database (docs_internal symlink). - muse-tmux: non-TTY attach falls back to scrollback capture; prune NameError fix. - box/muse passthrough for tmux/muse/docs; thread list/view alias + prefix resolve. - Docs: AGENTS.md, AGENT-TOOLING.md, BOX-WEB-SURFACE-GUIDE.md, README. - Tests: key-approval + passkey tests; sync stale sidechat UUIDs and manifest name. - .gitignore runtime trackers (subagent-sessions, conversation-nudge-tracker).
This commit is contained in:
@@ -39,12 +39,15 @@ flowchart LR
|
||||
### Trust & Identity Principles
|
||||
1. **Host as Source of Truth (`bl`)**: All mutating state, cryptographic keys, job definitions, variables, and browser CDP relays reside on `bl`. The VM does not persist authoritative fleet state.
|
||||
2. **On-Demand Tailnet SSH Bridge**: The VM board service bridges into allowlisted verbs in [`bin/box-ctl.py`](file:///home/super/Projects/NetVM/bin/box-ctl.py) using an on-demand Tailnet SSH connection (`super@100.123.153.75`).
|
||||
3. **Session Authentication & Brute-Force Defense**:
|
||||
3. **Session Authentication & Passkey Location Reality**:
|
||||
- Operator console access is unlocked via `POST /api/ops/login` with operator PIN `3128`, establishing cookie `ops_session`.
|
||||
- **Crucial Passkey Reality**: In reality, the passkey material is stored in a **single file (`.txt`) on the Google Cloud VM (`34.139.37.135`)**, **NOT on the dedicated BL (`100.123.153.75`)**.
|
||||
- Operators frequently forget this passkey; retrieve anytime via `box passkey` or from the text file on the VM.
|
||||
- Successful PIN logins bypass the rate limiter. Failed attempts are constrained by a 10-attempt sliding window.
|
||||
4. **Agent-Scoped Privacy Tiers**:
|
||||
4. **Agent-Scoped Privacy Tiers & Approval Flow**:
|
||||
- `ops_session` grants unredacted administrative visibility across all DMs, logs, loops, and actions.
|
||||
- Unauthenticated or agent-scoped queries receive redacted logs filtered to their respective identities.
|
||||
- **Agent Key Requests**: Agents do not hold administrative keys directly and must never hunt on `bl` for secrets. When elevated key access or approval is required, agents signal `APPROVAL_NEEDED: <details>` in task sidechats (or exit code 2). Operators verify and fulfill from the single `.txt` file on the VM.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user