From 2eb8c14c3ee50caf2adbbd58b60f93c8f54b7af0 Mon Sep 17 00:00:00 2001 From: verlyn13 Date: Wed, 19 Aug 2026 18:50:51 -0800 Subject: [PATCH 1/3] docs: de-link the parent organization from public prose and paths system-config is public and now has outside readers. The parent org carries linkPolicy "no-link" / publicAlias "parent organization" in the identity registry, but its real name appeared 142 times across 40 tracked files. This sweep removes the 100 incidental occurrences -- doc prose, filesystem paths, the org domain, and a Google Workspace super-admin mailbox published beside the gcloud invocation that uses it. Highest-value single change: docs/google-admin-tooling.md went from 15 occurrences to 0. Substitutions: Organizations/the-nash-group -> Organizations/ the-nash-group -> Nash-Group -> parent-organization The Nash Group / Nash Group -> the parent organization @thenash.group -> @ thenash.group -> Deliberately NOT changed, and why: - Structural identifiers other things resolve against: the SSH host alias github.com-nash-group, the key filename id_ed25519_nash-group, and the 1Password item path ssh/workstation/nash-group/github. Renaming the prose while the identifier stays would make the docs wrong. - iterm2/profiles/*.json and the four docs describing them. The profile filenames and Bound Hosts globs are matched at runtime; the docs must keep naming them accurately. - policies/host-capability-substrate/tiers.yaml, byte-pinned by a sibling repo -- coordinated re-vendor only. 42 occurrences remain, all structural. This reduces exposure; it does not de-link the organization, because two tracked FILENAMES still carry the name. Completing that requires renaming live artifacts and a vault item, which is a separate operator-gated change. Validation: scripts/validate-repo.sh PASS. No structural file appears in the diff (asserted explicitly). --- docs/agentic-tooling.md | 2 +- docs/cloudflare-mcp.md | 2 +- docs/cloudflare-one-terminology.md | 2 +- docs/codex-cli-setup.md | 2 +- docs/device-admin/README.md | 2 +- ...oudflare-dns-handback-ingest-2026-05-14.md | 4 +- ...re-windows-multi-user-ingest-2026-05-15.md | 2 +- docs/device-admin/current-status.yaml | 4 +- ...posture-cloudflare-tailscale-2026-05-18.md | 2 +- ...-remote-admin-routing-design-2026-05-13.md | 6 +-- ...or-device-access-proof-input-2026-05-18.md | 6 +-- ...dback-request-cloudflare-dns-2026-05-13.md | 2 +- ...flare-dns-windows-multi-user-2026-05-15.md | 2 +- ...lare-zero-trust-full-context-2026-05-16.md | 52 +++++++++---------- ...are-management-status-ingest-2026-05-14.md | 6 +-- ...ilscale-roaming-admin-report-2026-05-27.md | 10 ++-- docs/device-admin/onboarding-2026-05-12.md | 4 +- docs/google-admin-tooling.md | 30 +++++------ .../0001-repo-boundary-decision.md | 4 +- .../2026-04-24-control-plane-broker-design.md | 2 +- .../project-substrate-adoption.md | 8 +-- docs/iterm2-profile-redesign.md | 4 +- docs/project-conventions.md | 2 +- docs/restart-handoff-2026-08-08.md | 2 +- docs/secrets.md | 2 +- .../security-hardening-implementation-plan.md | 26 +++++----- docs/sentry-cli-setup.md | 2 +- .../project-substrate-admission.yaml | 8 +-- 28 files changed, 100 insertions(+), 100 deletions(-) diff --git a/docs/agentic-tooling.md b/docs/agentic-tooling.md index 1bbedc1..7ca9c78 100644 --- a/docs/agentic-tooling.md +++ b/docs/agentic-tooling.md @@ -194,7 +194,7 @@ Project agents stop before direct host mutation, Proxmox console drift, unscoped machine identities, secret material in files or state, and workloads without a reviewed substrate contract. The contract shape comes from Citadel's example at -`/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml`. +`/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml`. ## MCP Configuration diff --git a/docs/cloudflare-mcp.md b/docs/cloudflare-mcp.md index 24ea0d3..fbcc5de 100644 --- a/docs/cloudflare-mcp.md +++ b/docs/cloudflare-mcp.md @@ -81,7 +81,7 @@ instead of being preserved as user-added servers. Interim OAuth identity is `REDACTED-operator-google-account` (Option B) per the operator Cloudflare admin identity decision. The target identity is -`guardian@thenash.group` (Option C) after the Phase 2 Cloudflare account email +`@` (Option C) after the Phase 2 Cloudflare account email migration lands. The interim OAuth grant is read-mostly per the parent OAuth pilot findings: diff --git a/docs/cloudflare-one-terminology.md b/docs/cloudflare-one-terminology.md index 273efcb..421fe5d 100644 --- a/docs/cloudflare-one-terminology.md +++ b/docs/cloudflare-one-terminology.md @@ -22,7 +22,7 @@ Cloudflare, device, DNS, Tunnel, Access, Traffic policy, or 1Password change. ## Current Cloudflare Authority As of 2026-05-27, the active family-home Cloudflare control-plane repo is -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. +`/Users/verlyn13/Organizations//family-cloudflare`. That repo is the migration target from the older `/Users/verlyn13/Repos/local/cloudflare-dns` clone. Dated `cloudflare-dns` diff --git a/docs/codex-cli-setup.md b/docs/codex-cli-setup.md index 72fb6c0..e6236fc 100644 --- a/docs/codex-cli-setup.md +++ b/docs/codex-cli-setup.md @@ -62,7 +62,7 @@ boundary: | Full access | **OFF** (standing) | "Full access ON" is capability-availability, not a proven runtime grant — effective enforcement is `config.toml` Sandbox + Approval. Leaving it ON while relying on the sandbox to neutralize it is fragile and conflicts with the approval-gated posture: Full access = no-approval edits to *any* file, which can reach outside the workspace. | | Sandbox | **Read only** (default); `workspace-write` per-task only | Default-deny writes; widen only for a specific task. | | Approval | **On request** | Keep a human in the loop for actions outside the read-only sandbox. | -| Config selection | **jefahnierocks (entity) scope**, not `the-nash-group` | `the-nash-group` points the active config at **parent** scope while the work tree is the jefahnierocks **entity** — a boundary mismatch. Alternatively adopt a jefahnierocks-rooted project `.codex/config.toml` with `trust_level` opt-in. | +| Config selection | **jefahnierocks (entity) scope**, not `` | `` points the active config at **parent** scope while the work tree is the jefahnierocks **entity** — a boundary mismatch. Alternatively adopt a jefahnierocks-rooted project `.codex/config.toml` with `trust_level` opt-in. | Posture model: **HCS ADR 0017** (cited by identifier) — *UI labels are not runtime receipts*. The app's GUI permission rows are SOURCE/posture evidence, not diff --git a/docs/device-admin/README.md b/docs/device-admin/README.md index b8f3fc5..d507a7f 100644 --- a/docs/device-admin/README.md +++ b/docs/device-admin/README.md @@ -24,7 +24,7 @@ policies; older dated evidence may still say WARP, Zero Trust profile, or Gateway policy where that was the source-era wording. Current Cloudflare control-plane authority is -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, migrated from +`/Users/verlyn13/Organizations//family-cloudflare`, migrated from the older `/Users/verlyn13/Repos/local/cloudflare-dns` repo. Dated `cloudflare-dns` handbacks remain historical evidence; new Cloudflare blockers and proof requests should route to `family-cloudflare`. diff --git a/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md b/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md index 8554f45..aedfab1 100644 --- a/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md +++ b/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md @@ -24,7 +24,7 @@ was changed by this ingest. Current-state note, added 2026-05-27: this remains the historical ingest from the former `cloudflare-dns` repo. Active family-home Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use this +`/Users/verlyn13/Organizations//family-cloudflare`. Use this document for provenance, but refresh new Cloudflare One Client, device-profile, Gateway, Access, Tunnel, DNS, Worker, or Pulumi/IaC claims against `family-cloudflare` or live provider proof. @@ -39,7 +39,7 @@ Traffic policies for Gateway policies. | Field | Value | |---|---| -| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` as of 2026-05-27) | +| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations//family-cloudflare` as of 2026-05-27) | | Source doc | `docs/handback-system-config-2026-05-13.md` | | Source commit | `b5b9460` (file introduction) | | Parent context commit | `9e4458a` (`fix(state): correct stale enabled flag for 05-adult-identity-bypass`) | diff --git a/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md b/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md index 0eb7d5a..e98136c 100644 --- a/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md +++ b/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md @@ -24,7 +24,7 @@ package, or CLI surface. Current-state note, added 2026-05-27: the original follow-up was aimed at the pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work now -belongs in `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, so +belongs in `/Users/verlyn13/Organizations//family-cloudflare`, so that repo must answer or supersede this rebaseline before any Windows cutover. ## Source diff --git a/docs/device-admin/current-status.yaml b/docs/device-admin/current-status.yaml index bc1594f..4323a71 100644 --- a/docs/device-admin/current-status.yaml +++ b/docs/device-admin/current-status.yaml @@ -51,7 +51,7 @@ last_updated: 2026-05-28T07:23:14Z cloudflare_control_plane_current_state: verified_at: 2026-05-27T19:28:29Z active_repo: family-cloudflare - active_repo_path: /Users/verlyn13/Organizations/the-nash-group/family-cloudflare + active_repo_path: /Users/verlyn13/Organizations//family-cloudflare active_repo_head: 8bc7f11 active_repo_branch: docs/fu-23-warp-overlay-coexistence-2026-05-27 active_repo_upstream_state: "no upstream tracking branch; main and origin/main both at 8bc7f11" @@ -845,7 +845,7 @@ cross_cutting_tbd_items: advisory_ingests: - source_repo: hetzner - source_path: /Users/verlyn13/Organizations/the-nash-group/hetzner + source_path: /Users/verlyn13/Organizations//hetzner source_doc: docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md source_commit: 009c091bc63556e6fb43503bf70aee97a269ea82 ingested_at: 2026-05-14T17:30:00Z diff --git a/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md b/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md index 1a033e1..2d7e05a 100644 --- a/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md +++ b/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md @@ -28,7 +28,7 @@ term. Current-state note, added 2026-05-27: Cloudflare authority has migrated from the historical `cloudflare-dns` repo to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use the old +`/Users/verlyn13/Organizations//family-cloudflare`. Use the old handbacks below for provenance only; current Cloudflare One Client, Access, Tunnel, and profile claims need `family-cloudflare` or live provider proof. diff --git a/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md b/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md index 8e11d34..4d2d083 100644 --- a/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md +++ b/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md @@ -37,7 +37,7 @@ the `cloudflare-warp` package name remain literal. Current-state note, added 2026-05-27: this design predates the migration from `/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Keep the +`/Users/verlyn13/Organizations//family-cloudflare`. Keep the design conclusions, but refresh Cloudflare-side evidence in `family-cloudflare` before authoring or applying any cutover packet. @@ -80,7 +80,7 @@ This design crosses three repos. The boundary is strict: |---|---|---|---| | Host hardening, host firewall, host package state, host SSH config, host daemon state | `system-config` (this repo) | All of it. | This document, packets, apply records. | | LAN routing, OPNsense rules, ISC DHCP, Unbound DNS, NAT, HAProxy frontends, WoL | HomeNetOps (`~/Repos/verlyn13/HomeNetOps`) | All LAN-layer state. | "We need " requests via the handback-format pattern; never reach in. | -| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need " requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. | +| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations//family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need " requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. | Implication: any statement in any subsequent packet of the form "the Cloudflare Access policy for `fedora-top` is N" must cite a @@ -527,4 +527,4 @@ boundaries, nothing more. - [../secrets.md](../secrets.md) - HomeNetOps repo (external authority): `~/Repos/verlyn13/HomeNetOps` - `family-cloudflare` repo (external authority): - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` + `/Users/verlyn13/Organizations//family-cloudflare` diff --git a/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md b/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md index 1c1ab23..c11ce53 100644 --- a/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md +++ b/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md @@ -50,8 +50,8 @@ device profile, and Traffic policies. Operator-relayed parent packets: -- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md` -- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md` +- `/Users/verlyn13/Organizations//.claude/orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md` +- `/Users/verlyn13/Organizations//.claude/orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md` System-config sources: @@ -215,7 +215,7 @@ Record PASS/FAIL/date only. Do not commit screenshots. 1. From the travel MacBook's normal operator browser profile, open the Cloudflare dashboard. -2. Confirm the Nash Group / expected Cloudflare parent account is selectable. +2. Confirm the parent organization / expected Cloudflare parent account is selectable. 3. Confirm the Cloudflare One dashboard / `homezerotrust` context can be reached without changing any settings. 4. Record: diff --git a/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md b/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md index 94c1a68..c7e3fd8 100644 --- a/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md +++ b/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md @@ -20,7 +20,7 @@ Cloudflare One Client + `cloudflared` cutover packets for the household fleet. Current-state note, added 2026-05-27: this request was answered by the pre-migration `cloudflare-dns` repo and remains historical provenance. Active Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; new packets +`/Users/verlyn13/Organizations//family-cloudflare`; new packets must refresh current claims there or against live provider proof. `family-cloudflare` is now the active authority for Cloudflare account and team diff --git a/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md b/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md index cf9a3f7..bcbcba1 100644 --- a/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md +++ b/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md @@ -24,7 +24,7 @@ unless the operator separately authorizes that work in the Current-state note, added 2026-05-27: this request was originally addressed to the pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; that repo +`/Users/verlyn13/Organizations//family-cloudflare`; that repo must answer or supersede this request before any Windows multi-user cutover. ## Why This Exists diff --git a/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md b/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md index 52e3447..7fbc4de 100644 --- a/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md +++ b/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md @@ -170,12 +170,12 @@ state (current-status.yaml, system-wide section - **Identity providers configured in Cloudflare One:** Google OAuth + email OTP. -- **Cloudflare account name:** `The Nash Group`. +- **Cloudflare account name:** `the parent organization`. - **Cloudflare account ID:** `13eb584192d9cefb730fde0cfd271328`. - **Team name:** `homezerotrust` (team domain `homezerotrust.cloudflareaccess.com`). - **Account ownership scope (important):** the Cloudflare - account is at the **Nash Group parent level**, not the + account is at the **parent organization parent level**, not the jefahnierocks-entity level. jefahnierocks devices, identities, and zones (including `jefahnierocks.com`) are tenants under this parent account. See §6 Scope Boundaries below. @@ -200,11 +200,11 @@ This means: - For the device-level cutovers this handback unblocks (Cloudflare One Client enrollment for fedora-top / MAMAWORK / DSJ; SSH Tunnel + Access for off-LAN admin), the design should work with - whatever operator identity Nash-Group IAM eventually settles + whatever operator identity parent-organization IAM eventually settles on, and not bake assumptions in. - Recommendation either way: design **as if** there will be a separate operator-tier profile (call it `Operator` for now) - distinct from `Adults`. If Nash-Group IAM later resolves + distinct from `Adults`. If parent-organization IAM later resolves Jeff's identity to plain `Adults`, the Operator profile can be merged or aliased. The reverse (designing only for Adults then having to split out later) is worse. @@ -606,11 +606,11 @@ clarification 2026-05-16: ### Account / ownership -- **Cloudflare account name:** `The Nash Group`. +- **Cloudflare account name:** `the parent organization`. - **Cloudflare account ID:** `13eb584192d9cefb730fde0cfd271328`. - **Team name:** `homezerotrust`. - **Team domain:** `homezerotrust.cloudflareaccess.com`. -- **Account scope:** Nash Group (parent). jefahnierocks devices +- **Account scope:** parent organization (parent). jefahnierocks devices + zones (including `jefahnierocks.com`) are tenants under this parent account. See §6 Scope Boundaries. - **IaC:** Pulumi TypeScript in the `family-cloudflare` repo @@ -661,7 +661,7 @@ operator clarifications above, system-config recommends the designer evaluate **at least these candidate additions**: - **`Operator`** profile for Jeff (distinct from `Adults`). - Even if Nash-Group IAM eventually resolves Jeff's identity + Even if parent-organization IAM eventually resolves Jeff's identity to plain Adults, designing as if Operator-tier exists is cheaper than retrofitting. - **`Adults-Ahnie`** profile (kid-coexistence-aware adult, @@ -688,10 +688,10 @@ Cloudflare design touches: | Scope | Owner repo / entity | What it owns | What it does NOT own | |---|---|---|---| -| Parent governance | `the-nash-group` (parent entity) | Cloudflare account `The Nash Group` (`13eb584192d9cefb730fde0cfd271328`); cross-entity IAM and identity planning; standards; audit | Day-to-day device admin; per-family-member identity assignment; entity branding | -| Cloudflare IaC | `family-cloudflare` (managed by parent for all entities) | Pulumi TypeScript for the Nash Group Cloudflare account - Cloudflare One Client device profiles, Traffic policies, Access apps, Tunnels, DNS, managed networks, beacon registration | jefahnierocks-side device packets; operator-side Cloudflare One Client enrollment; identity-source decisions (those are IAM-planning scope) | -| Family device admin (this entity) | `jefahnierocks` (entity, `~/Organizations/jefahnierocks/`) | Device inventory and admin packets for family devices; per-device 1Password admin SSH keys; family identity-to-device mapping (Jeff / Ahnie / Axel / Wyn / Ila); fleet lifecycle | Cloudflare account or Pulumi state; Litecky-business resources; HomeNetOps LAN config; The Nash Group standards | -| Operator workspace + chezmoi orchestration | `system-config` (under jefahnierocks, this repo) | The operator MacBook config (chezmoi, mise, direnv, MCP, SSH client conf.d, 1P SSH agent integration); the device-admin packet ceremony (windows-terminal-admin-spec, packet-defect halt rule, etc.); operator-side Cloudflare One Client enrollment procedure | Cloudflare server-side; Pulumi state; Nash-Group IAM; what identities exist; LAN infrastructure | +| Parent governance | `` (parent entity) | Cloudflare account `the parent organization` (`13eb584192d9cefb730fde0cfd271328`); cross-entity IAM and identity planning; standards; audit | Day-to-day device admin; per-family-member identity assignment; entity branding | +| Cloudflare IaC | `family-cloudflare` (managed by parent for all entities) | Pulumi TypeScript for the parent organization Cloudflare account - Cloudflare One Client device profiles, Traffic policies, Access apps, Tunnels, DNS, managed networks, beacon registration | jefahnierocks-side device packets; operator-side Cloudflare One Client enrollment; identity-source decisions (those are IAM-planning scope) | +| Family device admin (this entity) | `jefahnierocks` (entity, `~/Organizations/jefahnierocks/`) | Device inventory and admin packets for family devices; per-device 1Password admin SSH keys; family identity-to-device mapping (Jeff / Ahnie / Axel / Wyn / Ila); fleet lifecycle | Cloudflare account or Pulumi state; Litecky-business resources; HomeNetOps LAN config; the parent organization standards | +| Operator workspace + chezmoi orchestration | `system-config` (under jefahnierocks, this repo) | The operator MacBook config (chezmoi, mise, direnv, MCP, SSH client conf.d, 1P SSH agent integration); the device-admin packet ceremony (windows-terminal-admin-spec, packet-defect halt rule, etc.); operator-side Cloudflare One Client enrollment procedure | Cloudflare server-side; Pulumi state; parent-organization IAM; what identities exist; LAN infrastructure | **Implications for the Cloudflare designer:** @@ -704,11 +704,11 @@ Cloudflare design touches: `desktop-2jj3187-warp-enrollment-cutover-packet`, `fedora-top-warp-enrollment-cutover-packet`), each gated on family-cloudflare answering this handback. -- Operator Cloudflare admin identity is a Nash-Group IAM +- Operator Cloudflare admin identity is a parent-organization IAM decision (not jefahnierocks scope). Design with that separation in mind. - Litecky Editing Services (Ahnie's business) is a separate - entity under Nash Group with its own repo + entity under parent organization with its own repo (`~/Organizations/litecky-editing/`). For now, Ahnie's Cloudflare identity is jefahnierocks-managed (`ahnielitecky@gmail.com`) because device management is routed through jefahnierocks. @@ -793,7 +793,7 @@ that answers, at minimum: policy each, what's the assignment rule. 2. **Jeff's profile placement** — Adults or a new `Operator` / `Admin` profile? Note that the actual Cloudflare admin - identity for Jeff is a **Nash-Group IAM decision** (not + identity for Jeff is a **parent-organization IAM decision** (not jefahnierocks); recommend designing as if a separate Operator tier exists, then aliasing if IAM-planning collapses it back to Adults. @@ -847,16 +847,16 @@ that answers, at minimum: - Wyn: `wynrjohnson@gmail.com`. - Ila: `ilagenevievemary@gmail.com`. - **Outstanding identity decision is Nash-Group scope, not + **Outstanding identity decision is parent-organization scope, not jefahnierocks:** Jeff's actual Cloudflare admin identity (Happy Patterns work email vs. personal Gmail vs. some - other) is part of broader IAM planning at the Nash Group - parent. family-cloudflare can either (a) wait for Nash-Group + other) is part of broader IAM planning at the parent organization + parent. family-cloudflare can either (a) wait for parent-organization IAM to resolve before finalizing operator-tier Access policies, or (b) design with a placeholder operator identity that can be re-mapped when IAM-planning lands. Operator preference: do not block jefahnierocks device - cutovers on Nash-Group IAM planning; design with a + cutovers on parent-organization IAM planning; design with a placeholder. ### Operator-roaming policy @@ -953,7 +953,7 @@ operator's admin capability — fully or partially. | **MacBook physical loss / theft (non-compromise)** | Same as death; but with credential rotation as precaution | Same as death; plus pre-emptive 1P session invalidation + GitHub token rotation + Cloudflare session invalidation | | **MacBook stolen, awake, unlocked, 1P agent unlocked** | Catastrophic: everything reachable from MacBook is in adversarial hands until the operator-side blast radius is contained | Emergency session-invalidation from any other 1P-capable device; rotate every per-device admin SSH key (the agent could still be unlocked); rotate every API token in 1P that was last used recently | | **1Password account compromised (separate from MacBook)** | Every per-device admin SSH key is exposed; every API token in `Dev` vault is exposed | Full 1P recovery flow + Cloudflare/GitHub/Hetzner/every-provider rotation. Worse than MacBook theft. | -| **Cloudflare account compromised** | device profiles can be re-pointed; Access policies can be modified; Gateway can be turned off; Tunnels can be created against any host; `jefahnierocks.com` DNS can be rewritten | Nash-Group escalation; Cloudflare support recovery; potentially zone re-transfer | +| **Cloudflare account compromised** | device profiles can be re-pointed; Access policies can be modified; Gateway can be turned off; Tunnels can be created against any host; `jefahnierocks.com` DNS can be rewritten | parent-organization escalation; Cloudflare support recovery; potentially zone re-transfer | | **Cloudflare account suspended (billing/TOS)** | All Cloudflare One Client + Access + Tunnel + Gateway features stop. `jefahnierocks.com` DNS stops. Family internet may stop (depending on DNS dependency). | Resolve with Cloudflare; meanwhile fall back to LAN-direct admin (no off-LAN admin available) | | **Google account suspended / lost (jeffrey@happy-patterns.com)** | Loss of Cloudflare OAuth login (sign in as that identity). Loss of Workspace email. Possible cascade to GitHub if linked. | Google recovery flow. Email OTP fallback for Cloudflare (if configured per-profile). | | **GitHub access lost (token rotation, account lock)** | system-config repo + every other repo become inaccessible from operator | GitHub recovery flow; 1P-stored GitHub PAT recovery | @@ -961,7 +961,7 @@ operator's admin capability — fully or partially. | **Hetzner outage** | If cloudflared is on Hetzner only, all off-LAN admin breaks. If LAN connector exists too, off-LAN admin still works. | Wait for Hetzner. | | **Home LAN power outage** | All on-LAN admin targets unreachable; Synology beacon down (no managed-network detection). WoL on UPS-fed devices could still wake them. | UPS for critical gear (Synology, OPNsense). Off-LAN admin not helpful unless devices come up on a battery-backed switch. | | **Synology beacon cert/disk failure** | Cloudflare managed-network detection fails (devices think they're off-LAN even when home) | Re-deploy beacon (10-year cert is static; can be copied from backup). family-cloudflare Pulumi state should carry the fingerprint pin. | -| **Operator (Jeff) incapacitated / unreachable** | No admin can happen until Jeff recovers or successor is empowered. No documented successor today (see §8.5). | Nash-Group governance; needs pre-planning. | +| **Operator (Jeff) incapacitated / unreachable** | No admin can happen until Jeff recovers or successor is empowered. No documented successor today (see §8.5). | parent-organization governance; needs pre-planning. | ### 8.3 MacBook loss / theft / death scenarios (three flavors) @@ -1040,7 +1040,7 @@ Inputs the operator needs **to even start that flow**: | 1Password Secret Key (account-bind) | 1P emergency kit PDF | Must be stored offline (printed in safe, encrypted USB, etc.) | | Apple ID password | Operator brain / iCloud Keychain | If iCloud Keychain was on the lost MacBook, Apple recovery flow | | GitHub recovery codes / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator | -| Cloudflare account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator. Note Nash-Group scope. | +| Cloudflare account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator. Note parent-organization scope. | | Hetzner account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator | | Domain registrar (where `jefahnierocks.com` and `happy-patterns.com` are registered) recovery | Should be in 1P + offline | Currently: TBD-operator | @@ -1064,13 +1064,13 @@ enrollment + 2FA), not require persistent device fingerprinting. Jeff is sole admin. If Jeff is unavailable (vacation off-grid, incapacitated, unreachable for weeks, deceased), no one can -currently administer the family fleet. The Nash Group parent +currently administer the family fleet. the parent organization parent scope owns this concern (it's an IAM-succession question beyond jefahnierocks), but jefahnierocks records it here so the Cloudflare design accounts for it: - **Who is Jeff's emergency successor?** TBD-operator. Likely - a Nash-Group-trusted party. + a parent-organization-trusted party. - **What does the successor need access to?** At minimum: - 1P vault `Dev` (read access; admin would need write). - Cloudflare account (admin tier). @@ -1181,7 +1181,7 @@ architect them out: should encourage automated `cloudflared` updates on whichever host runs it. system-config can package this. - **Operator forgets which Cloudflare account is which.** When - Nash-Group manages multiple entities' Cloudflare resources, + parent-organization manages multiple entities' Cloudflare resources, the operator working on jefahnierocks devices can't accidentally mutate happy-patterns / litecky resources. family-cloudflare Pulumi state per-entity scoping helps; @@ -1302,9 +1302,9 @@ but family-cloudflare will need these to finalize) - [ ] **Jeff's Cloudflare admin identity** — Happy Patterns email, personal Gmail, or something else. **This is a - Nash-Group IAM-planning decision, not a jefahnierocks + parent-organization IAM-planning decision, not a jefahnierocks decision.** family-cloudflare should design with a placeholder - operator identity and re-map when Nash-Group IAM-planning + operator identity and re-map when parent-organization IAM-planning resolves. - [ ] **Hetzner inventory** — count of servers, role(s), public IP(s). Needed only if the designer wants to recommend Option diff --git a/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md b/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md index 89f0ab9..ff42763 100644 --- a/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md +++ b/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md @@ -24,7 +24,7 @@ this ingest. Current-state note, added 2026-05-27: this ingest predates the migration from `/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Treat +`/Users/verlyn13/Organizations//family-cloudflare`. Treat Cloudflare facts here as historical/advisory only; current Cloudflare authority is `family-cloudflare` or live provider proof. @@ -32,7 +32,7 @@ is `family-cloudflare` or live provider proof. | Field | Value | |---|---| -| Source repo | `/Users/verlyn13/Organizations/the-nash-group/hetzner` | +| Source repo | `/Users/verlyn13/Organizations//hetzner` | | Source report | `docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md` | | Source commit cited | `009c091bc63556e6fb43503bf70aee97a269ea82` (`docs: leave-clean status refresh post Phase 2 and post-transfer truth alignment (#23)`) | | Source inspection mode | repo-only at Hetzner-repo authoring time; no live server, dashboard, Cloudflare API, or 1Password read was performed for that report | @@ -160,7 +160,7 @@ repos. ## Related -- Hetzner repo source report (`/Users/verlyn13/Organizations/the-nash-group/hetzner/docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md`) +- Hetzner repo source report (`/Users/verlyn13/Organizations//hetzner/docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md`) - [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) - the historical outbound request. - [fedora-top-remote-admin-routing-design-2026-05-13.md](./fedora-top-remote-admin-routing-design-2026-05-13.md) - diff --git a/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md b/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md index 02aa2c1..9f9b5bb 100644 --- a/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md +++ b/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md @@ -99,11 +99,11 @@ HomeNetOps sources: Family-cloudflare sources: -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-overlay-coexistence.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/design-surfaces.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/managed-network-tls-beacon.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/architecture.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-overlay-coexistence.md` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/design-surfaces.md` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/managed-network-tls-beacon.md` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/architecture.md` +- `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` HomeNetOps stand-down sources: diff --git a/docs/device-admin/onboarding-2026-05-12.md b/docs/device-admin/onboarding-2026-05-12.md index f16cb07..4faeaf4 100644 --- a/docs/device-admin/onboarding-2026-05-12.md +++ b/docs/device-admin/onboarding-2026-05-12.md @@ -29,7 +29,7 @@ those to Cloudflare One Client, device profile, and Traffic policies. Current-state note, added 2026-05-27: Cloudflare control-plane authority has migrated from `/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Historical +`/Users/verlyn13/Organizations//family-cloudflare`. Historical `cloudflare-dns` requests and ingests remain provenance; current Cloudflare blockers and proof requests should route to `family-cloudflare`. @@ -201,7 +201,7 @@ Use these documents when starting an agent directly on the target device: | Outbound to cloudflare-dns | [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) | Historical request to `/Users/verlyn13/Repos/local/cloudflare-dns` for org-wide Cloudflare One / Cloudflare One Client / Access / Tunnel posture and per-device profile recommendations. Current claims must be refreshed in `family-cloudflare`. Non-secret only; no live Cloudflare change requested. | | Outbound to HomeNetOps | [handback-request-homenetops-2026-05-13.md](./handback-request-homenetops-2026-05-13.md) | Two-item request to `~/Repos/verlyn13/HomeNetOps`: (1) posture confirmation for fedora-top (no new rule requested); (2) static-DHCP reservation for MAMAWORK Ethernet MAC `B0-41-6F-0E-B7-B6` -> `192.168.0.101` plus Unbound host override `mamawork.home.arpa`. Mirrors the 2026-05-13 fedora-top pattern. Non-secret only. **Answered 2026-05-14** - see [mamawork-homenetops-lan-identity-2026-05-14.md](./mamawork-homenetops-lan-identity-2026-05-14.md). | | MAMAWORK mini-PC | [mamawork-homenetops-lan-identity-2026-05-14.md](./mamawork-homenetops-lan-identity-2026-05-14.md) | Ingest of the HomeNetOps PASS hand-back for MAMAWORK. OPNsense static DHCP reservation bound, Unbound override `mamawork.home.arpa -> 192.168.0.101`, LAN/igc1 ARP confirms IP-to-MAC, `dig` PASS from LAN resolver. The earlier TCP/22 timeout was Windows-side and has since been resolved for the MacBook admin lane. ARP `permanent=false` because MAMAWORK is host-static; switching to DHCP would activate ISC static-ARP defense (optional follow-up packet). | -| Hetzner (advisory) | [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) | Advisory-only ingest of `/Users/verlyn13/Organizations/the-nash-group/hetzner` commit `009c091`. Hetzner brokers Cloudflare Tunnel ingress for hosted apps (Infisical, Postal Web, runpod-review-webui); it is NOT a household device control plane. Encodes the decision to NOT route household device admin through Hetzner; preferred target remains Cloudflare One Client / Access via `family-cloudflare`; Tailscale stays transition/break-glass. Does not satisfy current `family-cloudflare` proof needs. | +| Hetzner (advisory) | [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) | Advisory-only ingest of `/Users/verlyn13/Organizations//hetzner` commit `009c091`. Hetzner brokers Cloudflare Tunnel ingress for hosted apps (Infisical, Postal Web, runpod-review-webui); it is NOT a household device control plane. Encodes the decision to NOT route household device admin through Hetzner; preferred target remains Cloudflare One Client / Access via `family-cloudflare`; Tailscale stays transition/break-glass. Does not satisfy current `family-cloudflare` proof needs. | | Fedora 44 laptop | [fedora-top-admin-backup-ssh-key-strategy-packet-2026-05-14.md](./fedora-top-admin-backup-ssh-key-strategy-packet-2026-05-14.md) | Prepared. Adds one additional `verlyn13` ED25519 admin public key to `fedora-top` `/home/verlyn13/.ssh/authorized_keys`, with the private half held only in 1Password (Dev vault on my.1password.com) and served via the 1Password SSH agent on a backup operator device. Keeps `AllowUsers verlyn13`. Keeps `PasswordAuthentication no`. Does not add any other admin user. Does not reuse the legacy MAMAWORK `DadAdmin_WinNet` key. Snapshot-backed rollback. Closes the single-MacBook dependency for fedora-top remote administration. | | MAMAWORK mini-PC | [mamawork-ssh-investigation-packet-2026-05-14.md](./mamawork-ssh-investigation-packet-2026-05-14.md), [mamawork-inbound-tcp-blackhole-remediation-apply-2026-05-14.md](./mamawork-inbound-tcp-blackhole-remediation-apply-2026-05-14.md), [mamawork-sshd-admin-match-block-apply-2026-05-14.md](./mamawork-sshd-admin-match-block-apply-2026-05-14.md) | SSH investigation/remediation chain. Scoped investigation found Windows network-identity drift; remediation restored LAN TCP/22 and TCP/3389 reachability from the MacBook. Admin auth still failed until the sshd admin Match block packet restored `AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys` for local Administrators. MacBook real-auth proof now returns `MamaWork` / `mamawork\jeffr`. | | MAMAWORK mini-PC | [mamawork-switch-to-dhcp-source-of-truth-packet-2026-05-14.md](./mamawork-switch-to-dhcp-source-of-truth-packet-2026-05-14.md) | Prepared, optional. Switches the MAMAWORK wired adapter from host-side static IP (`192.168.0.101` manual) to DHCP so the existing OPNsense reservation owns the address and ISC static-ARP defense can activate (currently `permanent=false`). Brief 2-10 second reconnect window. Intentionally separate from the SSH investigation packet so connectivity changes are not bundled with debugging. | diff --git a/docs/google-admin-tooling.md b/docs/google-admin-tooling.md index 04e8d17..86e0932 100644 --- a/docs/google-admin-tooling.md +++ b/docs/google-admin-tooling.md @@ -34,7 +34,7 @@ The active local configuration is intentionally neutral: | Config | Active | Account | Project | |--------|--------|---------|---------| -| `thenash-guardian` | yes | `guardian@thenash.group` | unset | +| `thenash-guardian` | yes | `@` | unset | | `default` | no | `jeffrey@happy-patterns.com` | `happy-playground-463417` | | `scopecam-production` | no | `REDACTED-operator-google-account` | `scopecam-qa` | | `scopecam-qa` | no | `REDACTED-operator-google-account` | `scopecam-qa` | @@ -45,12 +45,12 @@ relationship. Current auth state: -- `gcloud auth list` shows `guardian@thenash.group` as active. +- `gcloud auth list` shows `@` as active. - Application Default Credentials file shape is `authorized_user`, account - `guardian@thenash.group`, with no `quota_project_id`. + `@`, with no `quota_project_id`. - Token refresh currently requires a human Google reauthentication flow. A non-interactive check with - `gcloud auth print-access-token --account=guardian@thenash.group --quiet` + `gcloud auth print-access-token --account=@ --quiet` failed with "Reauthentication failed. cannot prompt during non-interactive execution." The same class of failure applies to `gcloud auth application-default print-access-token --quiet` until the @@ -63,10 +63,10 @@ Current auth state: - Installed package: `gam7 7.43.5` - `gam version` reports `GAM 7.43.05` - Config file: `/Users/verlyn13/.gam/gam.cfg` -- Active GAM section: `thenash.group` -- Domain: `thenash.group` -- Admin email: `guardian@thenash.group` -- Workspace-specific config dir: `/Users/verlyn13/.gam/thenash.group` +- Active GAM section: `` +- Domain: `` +- Admin email: `@` +- Workspace-specific config dir: `/Users/verlyn13/.gam/` The legacy binary `/Users/verlyn13/bin/gam7/gam` still exists but is not the primary PATH binary. Prefer the `pipx` managed `gam` shim unless a task is @@ -90,7 +90,7 @@ gam version Token refresh checks do not print token values: ```bash -gcloud auth print-access-token --account=guardian@thenash.group --quiet >/dev/null +gcloud auth print-access-token --account=@ --quiet >/dev/null gcloud auth application-default print-access-token --quiet >/dev/null ``` @@ -102,24 +102,24 @@ steps below. The preferred Guardian shape is: - active config: `thenash-guardian` -- active account: `guardian@thenash.group` +- active account: `@` - project: unset -- ADC account: `guardian@thenash.group` +- ADC account: `@` - ADC quota project: unset Repair commands: ```bash gcloud config configurations activate thenash-guardian -gcloud config set account guardian@thenash.group +gcloud config set account @ gcloud config unset project --quiet gcloud config set disable_usage_reporting true -gcloud auth login guardian@thenash.group --force -gcloud auth application-default login guardian@thenash.group --disable-quota-project +gcloud auth login @ --force +gcloud auth application-default login @ --disable-quota-project ``` -Complete both browser flows as `guardian@thenash.group`. Do not use +Complete both browser flows as `@`. Do not use `--update-adc` if it would copy an unrelated project binding into ADC. After login, rerun the token refresh checks above. diff --git a/docs/host-capability-substrate/0001-repo-boundary-decision.md b/docs/host-capability-substrate/0001-repo-boundary-decision.md index 4e715ec..c000f53 100644 --- a/docs/host-capability-substrate/0001-repo-boundary-decision.md +++ b/docs/host-capability-substrate/0001-repo-boundary-decision.md @@ -39,7 +39,7 @@ Parent research plan: [`../host-capability-substrate-research-plan.md`](../host- ### 1.1 Nash Covenant principles (cited as planning input) -From `~/Organizations/the-nash-group/the-covenant/PRINCIPLES.md`: +From `~/Organizations//the-covenant/PRINCIPLES.md`: 1. The Sacred Timeline is Linear and Clean 2. Every Commit Shall Speak Its Purpose @@ -777,7 +777,7 @@ Gated on: approval grants + audit hash chain + dashboard review + lease manager - [Tooling surface matrix](./tooling-surface-matrix.md) (v1.0.0+) - [Project substrate adoption](./project-substrate-adoption.md) (v0.1.0+) - [Target-repo templates](./templates/) -- `~/Organizations/the-nash-group/the-covenant/PRINCIPLES.md` — 16 principles +- `~/Organizations//the-covenant/PRINCIPLES.md` — 16 principles - [`docs/project-conventions.md`](../project-conventions.md) - [`docs/mcp-config.md`](../mcp-config.md) - [`docs/secrets.md`](../secrets.md) diff --git a/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md b/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md index 2cc4092..29cec02 100644 --- a/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md +++ b/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md @@ -207,7 +207,7 @@ not change the broker's other contracts: The identity transition is also part of the baseline. The interim operator OAuth identity is `REDACTED-operator-google-account` (Option B); the Phase C -target identity is `guardian@thenash.group`, with the Cloudflare account email +target identity is `@`, with the Cloudflare account email migration target date of 2026-07-15, per parent identifier `OPERATOR-CLOUDFLARE-ADMIN-IDENTITY-DECISION-2026-05-16.md`. The broker's typed-operation and lease-and-ledger contract is identity-agnostic, but a diff --git a/docs/host-capability-substrate/project-substrate-adoption.md b/docs/host-capability-substrate/project-substrate-adoption.md index aeb0c5a..fc4f64b 100644 --- a/docs/host-capability-substrate/project-substrate-adoption.md +++ b/docs/host-capability-substrate/project-substrate-adoption.md @@ -15,15 +15,15 @@ Host-local adoption guidance for project use of the shared substrate until HCS is primary for typed evidence and operation gating. Source authority: Citadel PR #37, merged to -`The-Nash-Group/citadel-config` at +`The-parent-organization/citadel-config` at `46c55857427af4b887194277bac2218c20b595b6`. Read with: - Citadel standard: - `/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/project-substrate-control-plane-standard.md` + `/Users/verlyn13/Organizations//the-citadel/docs/project-substrate-control-plane-standard.md` - Citadel example contract: - `/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml` + `/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml` - Host-local policy snapshot: [`../../policies/host-capability-substrate/project-substrate-admission.yaml`](../../policies/host-capability-substrate/project-substrate-admission.yaml) @@ -63,7 +63,7 @@ docs/infrastructure/project-substrate-contract.yaml Use the Citadel example contract shape at: ```text -/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml +/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml ``` The contract declares the workload lanes, owner, authority repo, resource diff --git a/docs/iterm2-profile-redesign.md b/docs/iterm2-profile-redesign.md index 665d70a..2835459 100644 --- a/docs/iterm2-profile-redesign.md +++ b/docs/iterm2-profile-redesign.md @@ -458,7 +458,7 @@ B6. **Current verification.** The installer passes with one managed profile and one managed color preset. `ng-doctor`'s iTerm2 category passes its current checks. It does not yet prove color import or badge behavior. B7. **Done.** `Guardian L0` and `Nash Repo` profiles add path-scoped visual -signaling for `/Users/verlyn13/Organizations/the-nash-group`. This is a +signaling for `/Users/verlyn13/Organizations/`. This is a documented exception to default project-path independence because the profile's purpose is to distinguish Parent L0 context from nested repo context. See `docs/iterm2-guardian-profiles.md`. @@ -539,7 +539,7 @@ be updated, ask for that explicitly after the repo work lands. | Default Bookmark | Installer sets it deterministically | Consistent setup across machines; matches "deterministic" goal. | | Shell-integration scope | Interactive only (skipped in agentic) | Preserves agentic startup budget. | | Clipboard write (`Allow Clipboard Access From Terminal`) | `false` on Dev (and inherited by SSH variant in Phase C) | Closes OSC 52 / OSC 1337 SetClipboard injection vector. This workstation runs agentic tools (Claude Code, Codex, MCP) that pipe untrusted remote text through the terminal — any such text containing a clipboard-write escape would silently overwrite the system clipboard. Industry default for hardened multi-host setups. Read access (paste) unaffected. Escape hatch: edit the field to `true` in `iterm2/profiles/00-dev.json` and re-run `scripts/install-iterm2-profiles.sh`; iTerm2 reloads dynamically. Add a sibling "Dev (clipboard)" profile only if friction emerges in practice — do not pre-build. Decided 2026-05-08. | -| Nash Guardian profiles | Path-scoped visual exception | The user explicitly wants Parent L0 and nested-repo visual separation for `~/Organizations/the-nash-group`; the exception is documented and does not set commands, env, working directories, or secrets. | +| Nash Guardian profiles | Path-scoped visual exception | The user explicitly wants Parent L0 and nested-repo visual separation for `~/Organizations/`; the exception is documented and does not set commands, env, working directories, or secrets. | | Jefahnierocks Explorer profiles | Path-scoped visual exception | The user explicitly wants personal Explorer and nested-repo visual separation for `~/Organizations/jefahnierocks`; the exception is documented and keeps clipboard/triggers/global preferences under existing policy. | | Happy Patterns Professional profiles | Path-scoped visual exception | The user explicitly wants professional org and nested-repo visual separation for `~/Organizations/happy-patterns`; the exception is documented and keeps clipboard/triggers/global preferences under existing policy. | diff --git a/docs/project-conventions.md b/docs/project-conventions.md index f840df6..671b050 100644 --- a/docs/project-conventions.md +++ b/docs/project-conventions.md @@ -502,7 +502,7 @@ docs/infrastructure/project-substrate-contract.yaml Use the Citadel example shape at: ```text -/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml +/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml ``` The live host-local adoption policy is diff --git a/docs/restart-handoff-2026-08-08.md b/docs/restart-handoff-2026-08-08.md index b00b211..8755e3a 100644 --- a/docs/restart-handoff-2026-08-08.md +++ b/docs/restart-handoff-2026-08-08.md @@ -113,7 +113,7 @@ three real clones: | Clone path | Verified live fact | | --- | --- | -| `/Users/verlyn13/Organizations/the-nash-group-github-profile` | Origin uses `github.com`, while the registry expects `github.com-nash-group`; local status already had 3 entries. The doctor prints this same clone as `parent-org/.github` in the remote check and `The-Nash-Group/.github` in the config-drift check. | +| `/Users/verlyn13/Organizations/-github-profile` | Origin uses `github.com`, while the registry expects `github.com-nash-group`; local status already had 3 entries. The doctor prints this same clone as `parent-org/.github` in the remote check and `The-parent-organization/.github` in the config-drift check. | | `/Users/verlyn13/Organizations/happy-patterns/apps/happy-patterns-org.github.io` | Clean worktree; origin uses `github.com`, while the registry expects `github.com-happy-patterns`; email/signing/host configuration also differs from the registered lane. | | `/Users/verlyn13/Organizations/happy-patterns/apps/scopecam` | Clean worktree on `development`; origin uses `github.com`, while the registry expects `github.com-happy-patterns`; email/signing/host configuration also differs from the registered lane. | diff --git a/docs/secrets.md b/docs/secrets.md index 7a05da8..ac8fa98 100644 --- a/docs/secrets.md +++ b/docs/secrets.md @@ -21,7 +21,7 @@ The structural shape of every 1Password item referenced from this repo (field names, label-uniqueness rules, `op://` URI semantics, the cleanup recipe for duplicate-label drift) is governed by Nash's **1Password Item Shape Standard** at -`~/Organizations/the-nash-group/.org/standards/op-item-shape.md`. +`~/Organizations//.org/standards/op-item-shape.md`. This file restates the *jefahnierocks-side* policy (which references are live, which agent operations are authorized) and inherits the structural diff --git a/docs/security-hardening-implementation-plan.md b/docs/security-hardening-implementation-plan.md index 59f48c7..d87b63e 100644 --- a/docs/security-hardening-implementation-plan.md +++ b/docs/security-hardening-implementation-plan.md @@ -34,7 +34,7 @@ new implementation language should use Cloudflare One Client, Cloudflare One dashboard, device profiles, and Traffic policies. Current Cloudflare control-plane authority, verified 2026-05-27, is -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. It is the +`/Users/verlyn13/Organizations//family-cloudflare`. It is the migration target from the old `/Users/verlyn13/Repos/local/cloudflare-dns` clone. This plan keeps older `cloudflare-dns` references only as audit provenance; new P9 decisions, provider proofs, and IaC references should route @@ -146,7 +146,7 @@ to entries under `~/Library/Logs/security-audit/2026-05-02-ua-wired/`. org-level Secure Web Gateway proxy toggle (TCP) is not enabled in Traffic Settings. - Adult-profile contract values per the current migration target - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` + `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` (the original audit cited the older `cloudflare-dns` path): `serviceModeV2.mode = "warp"`, `tunnelProtocol = "wireguard"`, `switchLocked = false`, `allowedToLeave = true`. Profile id matches the @@ -214,7 +214,7 @@ boundaries during normal operation. | P6 LaunchAgents | Host (`launchctl unload`) plus the originating project repo for any source fix | Agents whose origin tree is gone get unloaded and the plist removed; agents whose origin still exists get fixed in that repo. | | P7 MCP profiles | `system-config` (`scripts/sync-mcp.sh`, `scripts/mcp-servers.json`, `home/dot_local/bin/`) | Pure user-level baseline work. | | P8 agent memory | `~/.codex/memories/`, `~/.claude/` (host) | Personal review. The codex memory is the heavy carrier. | -| P9 Cloudflare One Client / Traffic policy enforcement | `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/` (Pulumi TypeScript transition repo covering Gateway DNS / Traffic policies, lists, device profiles, Cloudflare One Client enrollment Access app, Gateway DNS location); Cloudflare One dashboard (org admin only) for the Secure Web Gateway proxy toggle and 2 legacy unmanaged policies | Two distinct external surfaces. system-config does not own either. family-cloudflare/AGENTS.md is authoritative for the current Pulumi-side contracts. | +| P9 Cloudflare One Client / Traffic policy enforcement | `/Users/verlyn13/Organizations//family-cloudflare/` (Pulumi TypeScript transition repo covering Gateway DNS / Traffic policies, lists, device profiles, Cloudflare One Client enrollment Access app, Gateway DNS location); Cloudflare One dashboard (org admin only) for the Secure Web Gateway proxy toggle and 2 legacy unmanaged policies | Two distinct external surfaces. system-config does not own either. family-cloudflare/AGENTS.md is authoritative for the current Pulumi-side contracts. | | P10 ng-doctor posture | `system-config` (`home/dot_local/bin/executable_ng-doctor.tmpl`) | Pure repo work; designed to land last. | ## 1Password Context @@ -843,7 +843,7 @@ Preserve (do not touch during P5 cleanup): toggled off and back on, or the allowlist is reset as part of P5, the daemon must be re-added explicitly. Verify after any ALF change: `warp-cli status` should report `Connected`. Cross-check with - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-client.md` + `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-client.md` (current runbook for the Cloudflare One Client CLI-side contracts). Acceptance gates: @@ -1100,7 +1100,7 @@ Cloudflare One Client / Traffic policy state. system-config does not own either. | Surface | Scope | Owner of record | |---|---|---| -| `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/` (Pulumi TypeScript transition repo) | Gateway DNS / Traffic policies, custom-block / custom-block-content / custom-block-ads / custom-allow / custom-breakglass lists, three custom Cloudflare One Client device profiles (kids, adults, headless), default device profile (singleton import), managed networks / TLS beacon, Cloudflare One Client enrollment Access app, Gateway DNS location | family-cloudflare repo | +| `/Users/verlyn13/Organizations//family-cloudflare/` (Pulumi TypeScript transition repo) | Gateway DNS / Traffic policies, custom-block / custom-block-content / custom-block-ads / custom-allow / custom-breakglass lists, three custom Cloudflare One Client device profiles (kids, adults, headless), default device profile (singleton import), managed networks / TLS beacon, Cloudflare One Client enrollment Access app, Gateway DNS location | family-cloudflare repo | | Cloudflare One dashboard, NOT in Pulumi | Secure Web Gateway proxy toggle (Traffic Settings -> Network); two legacy unmanaged policies "Cert Pinning" (precedence 0) and "Block Malware" (precedence 9000) | org admin only | The system-config plan does **not** flip the Secure Web Gateway proxy @@ -1132,9 +1132,9 @@ Tasks before any policy decision: - Read the family-cloudflare architecture and posture docs first; they are the rationale source for both Pulumi-managed state and the dashboard toggle decision: - - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/architecture.md` - - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-client.md` - - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` + - `/Users/verlyn13/Organizations//family-cloudflare/docs/architecture.md` + - `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-client.md` + - `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` - historical import source, only if needed for provenance: `~/Repos/local/cloudflare-dns/state.json` - Verify or decide org-admin state in the Cloudflare One dashboard @@ -1216,7 +1216,7 @@ Proposed checks: - `launchagents_all_loaded_or_disabled` - `wireshark_chmodbpf_present_only_if_used` - `warp_connected_and_dns_gateway_enforced` — adults-profile expectations - per `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml`: + per `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml`: - `serviceModeV2.mode == "warp"` (display string `WarpWithDnsOverHttps`) - `tunnelProtocol == "wireguard"` - `switchLocked == false` @@ -1490,13 +1490,13 @@ External research consulted while drafting this plan (URLs as of 2026-05-02): ### Internal cross-repo references -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/AGENTS.md` — +- `/Users/verlyn13/Organizations//family-cloudflare/AGENTS.md` — current guardrails for the family-home Cloudflare overlay control plane -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/architecture.md` — +- `/Users/verlyn13/Organizations//family-cloudflare/docs/architecture.md` — system architecture, profile contracts, list contents, free-tier limits -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-client.md` — +- `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-client.md` — Cloudflare One Client enrollment + diagnostic runbook -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` — +- `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` — op:// template for current policy inputs - `~/Repos/local/cloudflare-dns/state.json` — historical machine-readable Pulumi state from the pre-migration repo; use only for provenance/import diff --git a/docs/sentry-cli-setup.md b/docs/sentry-cli-setup.md index 228daa8..3f6bbb9 100644 --- a/docs/sentry-cli-setup.md +++ b/docs/sentry-cli-setup.md @@ -49,4 +49,4 @@ purpose-named, kebab-case item title (for example, For the live system-wide secret-handling rules, see [`docs/secrets.md`](./secrets.md). For item-shape rules (naming, field uniqueness, label collisions), see the Nash 1Password Item Shape Standard at -`~/Organizations/the-nash-group/.org/standards/op-item-shape.md`. +`~/Organizations//.org/standards/op-item-shape.md`. diff --git a/policies/host-capability-substrate/project-substrate-admission.yaml b/policies/host-capability-substrate/project-substrate-admission.yaml index 996435b..142eabc 100644 --- a/policies/host-capability-substrate/project-substrate-admission.yaml +++ b/policies/host-capability-substrate/project-substrate-admission.yaml @@ -6,11 +6,11 @@ last_updated: "2026-05-06" source_authority: owner: the-citadel - repository: The-Nash-Group/citadel-config + repository: The-parent-organization/citadel-config pull_request: 37 merged_commit: 46c55857427af4b887194277bac2218c20b595b6 - standard_path: /Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/project-substrate-control-plane-standard.md - example_contract_path: /Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml + standard_path: /Users/verlyn13/Organizations//the-citadel/docs/project-substrate-control-plane-standard.md + example_contract_path: /Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml adoption_boundary: current_policy_owner: system-config @@ -61,7 +61,7 @@ ownership: contract: required_before_use: true recommended_project_path: docs/infrastructure/project-substrate-contract.yaml - example_shape_path: /Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml + example_shape_path: /Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml allowed_statuses: - draft - accepted From 4f839e85d2d4be8441b6423ceb0e7575472b7c86 Mon Sep 17 00:00:00 2001 From: verlyn13 Date: Wed, 19 Aug 2026 18:51:40 -0800 Subject: [PATCH 2/3] fix(ssh): move parent-org OpenBao host identity into machine data This 14-line template was the highest-value single artifact in the public repo. It published, together: the parent organization's real name, a publicly routable IPv4 (verified non-RFC1918), User root, and the operator key filename -- i.e. a no-link entity's secrets manager, by reachable address, with root login, in a repo carrying the operator's real identity on every commit. Host identity now comes from ~/.config/chezmoi/chezmoi.toml under [data.ssh.parent_org_openbao] (alias, host, user, identity_file). Machine data already lives outside the repo, so no value is committed. The block is guarded with `hasKey .ssh "parent_org_openbao"` rather than a bare lookup, because chezmoi runs with missingkey=error and a bare key would break rendering on any machine that has not been configured. With the key absent the file renders as comments explaining how to restore it, so `chezmoi apply --dry-run --force` stays clean. OPERATOR ACTION REQUIRED: add the [data.ssh.parent_org_openbao] table before the next `chezmoi apply`, or the live ~/.ssh/conf.d/tng-openbao.conf loses its Host entry and the alias stops resolving. The example values in the template are RFC 5737 documentation addresses, not the real ones. The source filename still carries the "tng" abbreviation. Renaming it is safe (the SSH config Include is a *.conf glob, and the alias now comes from machine data) but renames outside scripts/ and docs/ are ask-first per AGENTS.md, and chezmoi would orphan the old deployed file. Left for a separate decision. --- .../private_conf.d/tng-openbao.conf.tmpl | 32 +++++++++++++++---- 1 file changed, 26 insertions(+), 6 deletions(-) diff --git a/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl b/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl index 5a28c2c..6c70f2d 100644 --- a/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl +++ b/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl @@ -1,14 +1,34 @@ {{- $identityAgent := .ssh.identity_agent | default "~/Library/Group Containers/2BUA8C4S2C.com.1password/t/agent.sock" -}} -# The Nash Group OpenBao host +# Parent-organization OpenBao host # Managed by chezmoi # +# Host identity for this entry lives in MACHINE DATA +# (~/.config/chezmoi/chezmoi.toml), never in this repo. system-config is a +# PUBLIC repository: a reachable address plus a login user for a no-link +# entity's secrets manager must not be committed here. +# # Host-specific SSH policy belongs in ~/.ssh/conf.d modules so the generated # top-level ~/.ssh/config can stay small and reproducible. - -Host tng-openbao-1 46.225.220.249 - HostName 46.225.220.249 - User root +{{ if hasKey .ssh "parent_org_openbao" -}} +{{- $bao := .ssh.parent_org_openbao -}} +Host {{ $bao.alias }} {{ $bao.host }} + HostName {{ $bao.host }} + User {{ $bao.user }} IdentityAgent "{{ $identityAgent }}" IdentitiesOnly yes - IdentityFile ~/.ssh/tng-openbao-operator.pub + IdentityFile {{ $bao.identity_file }} PubkeyAuthentication unbound +{{- else -}} +# NOT CONFIGURED on this machine. +# +# To restore this host entry, add to ~/.config/chezmoi/chezmoi.toml under the +# existing [data.ssh] table (values are examples -- use the real ones): +# +# [data.ssh.parent_org_openbao] +# alias = "tng-openbao-1" +# host = "203.0.113.10" +# user = "root" +# identity_file = "~/.ssh/tng-openbao-operator.pub" +# +# Then re-run: chezmoi apply --dry-run --force (then without --dry-run) +{{- end }} From 444b8714e44d761ed79fe132c11b6a59c5ac0d06 Mon Sep 17 00:00:00 2001 From: verlyn13 Date: Wed, 19 Aug 2026 18:58:45 -0800 Subject: [PATCH 3/3] feat(validate): scan for parent-org name and non-allowlisted emails docs/git-identity.md presents identity_no_registry_values_committed as the control for "never commit registry.json or any value from it". Only the file half was ever implemented: that ng-doctor check greps git ls-files for a file NAMED registry.json and runs check-ignore. It performs no content inspection, and it reported green while 142 parent-org occurrences and 32 third-party personal email addresses sat in the tree. ng-doctor is also never executed by CI -- validate-repo.sh only shellchecks its template. Add two content scans to the gate CI actually runs. 1. Parent-org real name. Deliberately does not match a bare "nash-group", which only occurs inside identifiers that other things resolve against (github.com-nash-group, id_ed25519_nash-group, ssh/workstation/nash-group). 2. Email addresses outside an allowlist. The allowlist is what makes this runnable rather than permanently red: it passes vendor, RFC-reserved and operator-owned domains and fails personal and third-party addresses. Failure output for the email scan is MASKED to localpart-initial. CI logs on a public repo are themselves public, so echoing a matched address would publish, durably and indexably, the exact value the step exists to keep out. The org-name scan prints matching lines unmasked, which is correct -- that name is already public via the structural files below. Exclusions are structural, each a value something resolves against at runtime: iterm2/** profile filenames and Bound Hosts globs, docs/iterm2-*.md which document them, zz-iterm2.zsh's $PWD test, the byte-pinned tiers.yaml, tests/policies/** negative fixtures whose values ARE the test input, and home/.chezmoidata.yaml allowed_signers principals which must byte-match the signing identity or verification stops. Also fixes three name occurrences the doc sweep missed on case and hyphen variants -- two description fields in the SSH import manifests and one line in secret-records.md. The structural identifiers on those same lines are unchanged. NOTE: this gate FAILS on main until the PII redaction lands, which is the intended ordering, not a regression. shellcheck clean at the pinned 0.11.0. --- docs/secret-records.md | 2 +- scripts/import-ssh-keys.zsh | 2 +- scripts/validate-repo.sh | 68 ++++++++++++++++++++++++ scripts/write-1p-ssh-import-manifest.zsh | 2 +- 4 files changed, 71 insertions(+), 3 deletions(-) diff --git a/docs/secret-records.md b/docs/secret-records.md index 7c23d0e..8b6cfb0 100644 --- a/docs/secret-records.md +++ b/docs/secret-records.md @@ -45,7 +45,7 @@ Allowed statuses: `planned`, `issued`, `active`, `transitional`, `retired`, ## Known Cross-Boundary Tokens `TF_VAR_github_token` observed in the Happy Patterns GitHub UI is a separate -Happy Patterns to The-Nash-Group provider credential. It is not a +Happy Patterns to parent-organization provider credential. It is not a `system-config` MCP token and should not be stored under the `github-mcp`, `github-happy-patterns`, or `github-dev-tools` aliases. Treat it as cross-entity and transitional until the owning project records its logical diff --git a/scripts/import-ssh-keys.zsh b/scripts/import-ssh-keys.zsh index 139db3c..d26732d 100755 --- a/scripts/import-ssh-keys.zsh +++ b/scripts/import-ssh-keys.zsh @@ -51,7 +51,7 @@ write_manifest() { /Users/verlyn13/.ssh/id_ed25519_business_org ssh/workstation/business_org/github ssh,interactive,github,workstation,business_org GitHub identity for business-org variant. De-duplicate with business-org. /Users/verlyn13/.ssh/id_ed25519_hubofaxel ssh/workstation/hubofaxel/github ssh,interactive,github,workstation,hubofaxel Git SSH key for hubofaxel. /Users/verlyn13/.ssh/id_ed25519_hubofwyn ssh/workstation/hubofwyn/github ssh,interactive,github,workstation,hubofwyn Git SSH key for hubofwyn. -/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for Nash Group. +/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for the parent organization. /Users/verlyn13/.ssh/id_ed25519_documentation ssh/workstation/documentation/container ssh,workstation,documentation,container laptop-to-documentation-container access key. Provenance review; archive if unused. /Users/verlyn13/.ssh/id_ed25519_mac ssh/workstation/mac/cross-machine ssh,workstation,mac,cross-machine verlyn13@fedora-top cross-machine identity. Provenance review. /Users/verlyn13/.ssh/id_ed25519_scope ssh/workstation/scope/unknown ssh,workstation,scope,unknown Provenance unclear. Review before action. diff --git a/scripts/validate-repo.sh b/scripts/validate-repo.sh index 91dae32..70f8abb 100755 --- a/scripts/validate-repo.sh +++ b/scripts/validate-repo.sh @@ -81,4 +81,72 @@ if rg -n --hidden --glob '!.git' --glob '!scripts/validate-repo.sh' \ exit 1 fi +# Identity content scan. THIS REPO IS PUBLIC. +# +# The consumer contract in docs/git-identity.md forbids committing registry.json +# "or any value from it" -- author emails, key paths, the parent-org real name. +# Only the first half was ever enforced: ng-doctor's +# identity_no_registry_file_committed greps git ls-files for a file NAMED +# registry.json and runs check-ignore. It performs no content inspection, and it +# reported green while 142 parent-org occurrences and 32 third-party personal +# email addresses sat in the tree. This step is the missing half. +# +# Exclusions are structural, not cosmetic -- each is a value something resolves +# against at runtime, where changing it would break a mechanism or (for the +# byte-pinned file) require a coordinated re-vendor: +# iterm2/** profile filenames + APS "Bound Hosts" globs +# docs/iterm2-*.md document those globs; must stay accurate +# zz-iterm2.zsh $PWD equality test against the org path +# tiers.yaml byte-pinned by a sibling repo's vendored snapshot +# tests/policies/** negative fixtures; the values are the test input +# home/.chezmoidata.yaml allowed_signers principals must byte-match the +# signing identity or verification stops +identity_excludes=( + --glob '!.git' --glob '!scripts/validate-repo.sh' + --glob '!iterm2/**' --glob '!docs/iterm2-*.md' + --glob '!home/dot_config/zshrc.d/zz-iterm2.zsh' + --glob '!policies/host-capability-substrate/tiers.yaml' + --glob '!tests/policies/**' --glob '!home/.chezmoidata.yaml' +) + +# Parent-org real name. Deliberately does NOT match a bare "nash-group", which +# only ever occurs inside identifiers that are excluded above or are themselves +# the thing being resolved (github.com-nash-group, id_ed25519_nash-group, +# ssh/workstation/nash-group/github). +if rg -n --hidden "${identity_excludes[@]}" \ + 'the-nash-group|thenash\.group|Nash[- ]Group' \ + .; then + echo "Error: parent-organization real name found in this PUBLIC repo" >&2 + echo " The parent org is no-link / publicAlias 'parent organization'." >&2 + echo " Use , , or 'the parent organization'." >&2 + exit 1 +fi + +# Email addresses outside the allowlist. The allowlist is what makes this +# runnable: it passes vendor/docs/RFC-reserved addresses and the operator's own +# entity domains, and fails personal and third-party addresses. +email_allow='@(example\.[a-z]+|[a-z0-9.-]+\.example\.com|internal\.company\.com' +email_allow+='|[a-z0-9.-]+\.(home\.arpa|hq|invalid|local)' +email_allow+='|github\.com|users\.noreply\.github\.com|openssh\.com|libssh\.org' +email_allow+='|anthropic\.com|tailscale\.com|cloudflare\.com|sentry\.io' +email_allow+='|happy-patterns\.com|jefahnierocks\.com|hubofwyn\.com|hubofaxel\.com)' +# +# The failure output is MASKED. CI logs for a public repo are themselves +# public, so echoing a matched address here would publish the exact value this +# step exists to keep out -- and would do it on every failing run, in a +# durable, indexable place. Report file and localpart shape only. +email_hits=$(rg -o --hidden "${identity_excludes[@]}" \ + '[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}' \ + . | grep -vE "$email_allow" || true) +if [[ -n "$email_hits" ]]; then + echo "Error: non-allowlisted email address found in this PUBLIC repo" >&2 + echo "$email_hits" \ + | sed -E 's/:([A-Za-z0-9._%+-])[A-Za-z0-9._%+-]*@/:\1***@/' \ + | sort -u | sed 's/^/ /' >&2 + echo " Personal and third-party addresses must not be committed here." >&2 + echo " Use a REDACTED--google-account style placeholder." >&2 + echo " If the domain is legitimately public, add it to email_allow above." >&2 + exit 1 +fi + echo "system-config validation: PASS" diff --git a/scripts/write-1p-ssh-import-manifest.zsh b/scripts/write-1p-ssh-import-manifest.zsh index 48215ed..6bc7406 100755 --- a/scripts/write-1p-ssh-import-manifest.zsh +++ b/scripts/write-1p-ssh-import-manifest.zsh @@ -14,7 +14,7 @@ cat > "$MANIFEST_PATH" <<'EOF' /Users/verlyn13/.ssh/id_ed25519_business_org ssh/workstation/business_org/github ssh,interactive,github,workstation,business_org GitHub identity for business-org variant. De-duplicate with business-org. /Users/verlyn13/.ssh/id_ed25519_hubofaxel ssh/workstation/hubofaxel/github ssh,interactive,github,workstation,hubofaxel Git SSH key for hubofaxel. /Users/verlyn13/.ssh/id_ed25519_hubofwyn ssh/workstation/hubofwyn/github ssh,interactive,github,workstation,hubofwyn Git SSH key for hubofwyn. -/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for Nash Group. +/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for the parent organization. /Users/verlyn13/.ssh/id_ed25519_documentation ssh/workstation/documentation/container ssh,workstation,documentation,container laptop-to-documentation-container access key. Provenance review; archive if unused. /Users/verlyn13/.ssh/id_ed25519_mac ssh/workstation/mac/cross-machine ssh,workstation,mac,cross-machine verlyn13@fedora-top cross-machine identity. Provenance review. /Users/verlyn13/.ssh/id_ed25519_scope ssh/workstation/scope/unknown ssh,workstation,scope,unknown Provenance unclear. Review before action.