97f0e4e50e
- chmod 600 ~/.ssh/authorized_keys (already 600, verified) - sshd listening on :22, reverse tunnel VM 127.0.0.1:2226 -> container:22 up - authorized key present (super@bl); key-auth step belongs to key holder Fixes #213
1.4 KiB
1.4 KiB
Ticket #213 verification — SSH key perms and container dial-in (646)
Date: 2026-10-09 ~22:50 UTC
Operator: operator-646 (muse-646-patha)
Branch: dev/646/213-fix-ssh-perms
1. authorized_keys permissions (port 2226 dial-in)
~/.ssh/authorized_keys(/home/hatch/.ssh/authorized_keys):- before:
600 root:root - ran
chmod 600 ~/.ssh/authorized_keysper ticket - after:
600 root:root(no-op — already correct)
- before:
- sshd's requirement (private key file must not be group/world-writable,
ideally 600) is satisfied.
~/.sshitself is700.
2. Container sshd
sshdrunning (pid 2655, listener, 0 of 10-100 startups).- Listening on
0.0.0.0:22and[::]:22. authorized_keysholds 1 key:ssh-ed25519 SHA256:UOeqKF5BehWNmEpBSk53Qhz0Jd9aQXbFO0VKe2AVo8c(commentsuper@bl) — dial-in identity belongs to super.
3. Reverse tunnel (VM 2226 → container:22)
- On VM 34.139.37.135 (as dev-operator-646):
127.0.0.1:2226and[::1]:2226are LISTENING — the reverse tunnel is up. - Bind is loopback-only (no GatewayPorts), so dial-in must originate
from the VM itself — expected for
ssh -Rforwards.
4. Dial-in path verdict
Container-side prerequisites are all green: perms 600, sshd listening,
tunnel established, authorized key present. The final key-auth step can
only be completed by the holder of the super@bl private key, so no
full loopback auth was attempted from this operator identity.
Fixes #213