# Ticket #213 verification — SSH key perms and container dial-in (646) Date: 2026-10-09 ~22:50 UTC Operator: operator-646 (muse-646-patha) Branch: `dev/646/213-fix-ssh-perms` ## 1. authorized_keys permissions (port 2226 dial-in) - `~/.ssh/authorized_keys` (`/home/hatch/.ssh/authorized_keys`): - before: `600 root:root` - ran `chmod 600 ~/.ssh/authorized_keys` per ticket - after: `600 root:root` (no-op — already correct) - sshd's requirement (private key file must not be group/world-writable, ideally 600) is satisfied. `~/.ssh` itself is `700`. ## 2. Container sshd - `sshd` running (pid 2655, listener, 0 of 10-100 startups). - Listening on `0.0.0.0:22` and `[::]:22`. - `authorized_keys` holds 1 key: - `ssh-ed25519 SHA256:UOeqKF5BehWNmEpBSk53Qhz0Jd9aQXbFO0VKe2AVo8c` (comment `super@bl`) — dial-in identity belongs to super. ## 3. Reverse tunnel (VM 2226 → container:22) - On VM 34.139.37.135 (as dev-operator-646): `127.0.0.1:2226` and `[::1]:2226` are LISTENING — the reverse tunnel is up. - Bind is loopback-only (no GatewayPorts), so dial-in must originate from the VM itself — expected for `ssh -R` forwards. ## 4. Dial-in path verdict Container-side prerequisites are all green: perms 600, sshd listening, tunnel established, authorized key present. The final key-auth step can only be completed by the holder of the `super@bl` private key, so no full loopback auth was attempted from this operator identity. Fixes #213