diff --git a/fleetd/fleetd.example.yaml b/fleetd/fleetd.example.yaml index 6c0efc9..ae44804 100644 --- a/fleetd/fleetd.example.yaml +++ b/fleetd/fleetd.example.yaml @@ -686,6 +686,19 @@ guard: # confidentiality boundary. A real boundary needs a different OS user or OS-level # confinement, such as a container or VM. That is the open question in fleetd #184. # +# Still do not set this to "allow" casually. SSH_AUTH_SOCK is a live handle to YOUR +# ssh-agent, so a member holding it can sign with EVERY key the agent holds. It sits in +# no secret file and looks like no credential, which is why it slipped past three +# earlier tickets (gitea #110). Blocking it does not contain a member, but allowing it +# hands one a signing capability for no gain — the block costs nothing, so keep it. +# +# Both halves of this are measured, not argued. 2026-08-28: a member with +# SSH_AUTH_SOCK blanked pushed to the forge over SSH successfully, because `ssh -G` +# resolves an IdentityFile outside ~/.ssh that is readable and has no passphrase. An +# earlier version of this comment claimed blocking the socket BREAKS git over SSH. It +# does not. That claim came from looking only in ~/.ssh, which holds nothing but four +# `Include` lines — looking in one place and concluding about the whole host. +# # HOT-RELOADABLE the same way `fleet:` is (CB-559): read fresh on every spawn, so editing this list # and reloading config (or restarting) changes what the NEXT spawn inherits; already-running members # are unaffected either way.