Fleet changelogs · dev.ecs0.net
rdmbair15m5-changelog-20260823-0420-inbound-ssh-and-agent-alignment

rdmbair15m5-changelog-20260823-0420-inbound-ssh-and-agent-alignment

Repaired the one missing direct inbound SSH authorization on jdmbair13m5, verified the sixth Mac's bidirectional richh SSH paths, reconciled the canonical fleet document without losing newer peer edits, and aligned the managed Claude/Codex/Gemini fleet pointer across all six Macs.

Scope

Root cause

Port 22, Remote Login, LAN/Tailscale routing, and the pinned jdmbair13m5 server host key were healthy. Direct ssh -vv from rdmbair15m5 offered ED25519 fingerprint SHA256:JGCIHmjOi+WDA5hSe/hXRz5a9Azawgv7HkRWKw2EIyM, but jdmbair13m5 rejected it. The target's /Users/richh/.ssh/authorized_keys had five entries and was missing exactly that public key.

The earlier catch-up evidence had counted six keys on rdmbair15m5 itself; it did not prove that jdmbair13m5 authorized rdmbair15m5. The direct source-to-target probe exposed the distinction.

Changes

SSH authorization

Canonical onboarding records on rdmsm4x

Canonical fleet and project records on rdmsm4x

Six-host distribution

Verification evidence

Provider/runtime audit

Coordination

Persistence

Undo

  1. To undo only the SSH authorization, on the cryptographically pinned jdmbair13m5 restore /Users/richh/.ssh/backups/inbound-ssh-20260823-035406/authorized_keys.pre to /Users/richh/.ssh/authorized_keys, retain owner richh:staff and mode 0600, and rerun the direct matrix. This intentionally reintroduces the original rdmbair15m5 access failure.
  2. To undo canonical onboarding documentation, restore the two *.bak.20260823-0401-inbound-ssh files beside ISSUES.md and SESSION-STATE.md.
  3. To undo canonical fleet/project documentation, restore the named backups beside FLEET.md, FLEET-POINTER.md, and PROJECTS.md, then run sync_fleet_knowledge.zsh --dry-run and the actual sync from rdmsm4x.
  4. To undo a single host's distributed fleet document, restore that host's /Users/richh/.agent-coordination/FLEET.md.bak.20260823-0412-inbound-ssh and verify its recorded pre-hash.
  5. To restore the immediately preceding Claude context files, copy back /Users/richh/.claude/CLAUDE.md.bak.20260823-0417-inbound-ssh-pointer. To restore only the prior managed block in any harness, run the canonical _inject_block.py against that file using the backed-up old FLEET-POINTER.md and the existing begin/end markers.

Outstanding owner actions