diff --git a/ACCOUNTS.md b/ACCOUNTS.md new file mode 100644 index 0000000..6a14ed0 --- /dev/null +++ b/ACCOUNTS.md @@ -0,0 +1,43 @@ +# Login registry — secret-free + +Which product login lives in which chrome-box profile, on which NetVM node, +with which egress, in what auth state. This is structure only: **no +passwords, no tokens, no session cookies, no OTP codes — ever.** Credential +pointers at most (e.g. "human", "credential-gateway:"). + +The 1:1 chain: `login -> profile = node = Warp identity = veth/CDP slot = +consistent egress`. Network details live in NODES.md; this file maps the +human side (whose login, what for, does it work). + +## Auth states + +| state | meaning | who moves it | +|-------|---------|--------------| +| `pending-identity` | profile exists, no Warp identity yet | human runs `netvm-new-identity.sh ` | +| `pending-auth` | node up, nobody logged in yet | human logs in (browser or credential gateway) | +| `2fa-pending` | login needs a human 2FA/OTP step | human via ethical-captcha handoff; OTP routed by email-alert | +| `active` | logged in, session healthy | operator verifies; automation may proceed | +| `expired` | session died | back to `pending-auth` (human) | +| `retired` | login no longer used | operator tears down node, archives row | + +Operators never create or touch credentials. If it creates or touches a +credential, it is human-only. Everything else, operators handle. + +## Registry + +| login | product | profile/node | purpose / owner | auth state | 2FA / verify route | notes | +|-------|---------|--------------|-----------------|------------|--------------------|-------| +| — | — | tp | orchestrator / operator-main | pending-auth | — | first node; no product login yet | +| — | — | smoke | dev test rig | pending-auth | — | dedicated test profile; muse.ai loads, no login yet | + +## Provisioning a new login (dev) + +1. Operator: `chrome-box create ` (profile name = future node name). +2. Human: `netvm-new-identity.sh ` (Warp identity — credential). +3. Operator: `netvm-node-up.sh `; add rows to NODES.md and here + (`pending-identity` -> `pending-auth`). +4. Human: authenticate the login in the profile's browser + (`netvm-chrome.sh ` visible, or credential-gateway injection). + Row -> `active`. +5. Operator: verify with `netvm-exec.sh -- ...` / CDP; keep the + session warm. On 2FA: ethical-captcha handoff, OTP via email-alert.