diff --git a/docs/device-admin/README.md b/docs/device-admin/README.md index ce860da..eccef72 100644 --- a/docs/device-admin/README.md +++ b/docs/device-admin/README.md @@ -23,6 +23,11 @@ device-admin prose should say Cloudflare One Client, device profile, and Traffic policies; older dated evidence may still say WARP, Zero Trust profile, or Gateway policy where that was the source-era wording. +Dated packets preserve source-era observations, but are not whole-file privacy +exceptions. Private source locators use semantic ownership plus logical +repository/document/commit provenance, and later current-state notes and +instructions remain active prose. + Current Cloudflare control-plane authority is the owner-scoped `family-cloudflare` repository, migrated from the older `/Users/verlyn13/Repos/local/cloudflare-dns` repo. Locate current owner source diff --git a/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md b/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md index a7486eb..9bc73c8 100644 --- a/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md +++ b/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md @@ -24,7 +24,7 @@ was changed by this ingest. Current-state note, added 2026-05-27: this remains the historical ingest from the former `cloudflare-dns` repo. Active family-home Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use this +the owner-scoped `family-cloudflare` repository. Use this document for provenance, but refresh new Cloudflare One Client, device-profile, Gateway, Access, Tunnel, DNS, Worker, or Pulumi/IaC claims against `family-cloudflare` or live provider proof. @@ -39,7 +39,7 @@ Traffic policies for Gateway policies. | Field | Value | |---|---| -| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` as of 2026-05-27) | +| Source repo | `cloudflare-dns` (historical; migrated to the owner-scoped `family-cloudflare` repository as of 2026-05-27) | | Source doc | `docs/handback-system-config-2026-05-13.md` | | Source commit | `b5b9460` (file introduction) | | Parent context commit | `9e4458a` (`fix(state): correct stale enabled flag for 05-adult-identity-bypass`) | @@ -55,9 +55,9 @@ reply. ```text Cloudflare account: single account; owner REDACTED-operator-google-account -Cloudflare team: same account; team name "homezerotrust"; +Cloudflare team: same account; team name "[redacted historical Cloudflare team identifier]"; team domain - homezerotrust.cloudflareaccess.com + [redacted historical Cloudflare team domain] Machine identity for IaC: iac-automation@jefahnierocks.com API token storage: gopass under cloudflare/cloudflare-dns/* (NOT 1Password; this is a correction @@ -161,7 +161,7 @@ Naming convention for SSH once cloudflare-dns adopts them): logical name: access-app-ssh- dashboard label: SSH - - hostname: ssh-.homezerotrust.cloudflareaccess.com + hostname: [redacted historical Cloudflare team domain] No custom domain is registered for Access today. Default session duration: TBD. Recommended 8h (or 24h for @@ -180,7 +180,7 @@ Tunnel-name convention: TBD. Working candidate (Pulumi logical): tunnel- Per-tunnel hostname convention: TBD. Working candidate: - ssh-.homezerotrust.cloudflareaccess.com + [redacted historical Cloudflare team domain] (paired 1:1 with the Access app) Managed vs config.yml: Recommendation: managed-tunnel (dashboard + Pulumi); config.yml on @@ -213,7 +213,7 @@ Profile match: existing Kids profile (no Pulumi change needed) Effects of Kids placement: - Cloudflare One Client locked: Wyn cannot disconnect, cannot switch modes, - cannot leave the `homezerotrust` team; reconnect is instant. + cannot leave the `[redacted historical Cloudflare team identifier]` team; reconnect is instant. - All kids-controls Gateway DNS / Traffic policies apply (06-adult-themes, 07-ytrestricted, 08-safesearch, 09-content-block, 13-kids-social-block). @@ -223,7 +223,7 @@ Effects of Kids placement: First Linux enrollment: yes (no prior Cloudflare One Client enrollment on Linux in this fleet). Enrollment recipe: dnf install cloudflare-warp; - warp-cli registration new homezerotrust; + warp-cli registration new [redacted historical Cloudflare team identifier]; browser OAuth as REDACTED-wyn-google-account. ``` @@ -330,7 +330,7 @@ What this handback unlocks: | Lane | system-config side | Cloudflare authority side | What it unlocks | |---|---|---|---| | **Windows multi-user Cloudflare One Client** | install Cloudflare One Client on MAMAWORK after family-cloudflare confirms the MDM and enrollment recipe; register each Windows account with its intended identity | family-cloudflare rebaseline required for `multi_user=true`, profile policy, optional pre-login registration, and validation evidence | Admin/adult accounts avoid Kids controls; kid accounts keep Kids controls; does NOT add an off-LAN SSH admin path | - | **Cloudflare One Client + cloudflared Tunnel + Access** | install + start `cloudflared`; verify outbound 443 to Cloudflare edge | Pulumi commit adding the SSH Access application + the Tunnel + connector token | Off-LAN SSH admin path (`ssh ssh-.homezerotrust.cloudflareaccess.com`); supersedes any need for Tailscale break-glass once verified | + | **Cloudflare One Client + cloudflared Tunnel + Access** | install + start `cloudflared`; verify outbound 443 to Cloudflare edge | Pulumi commit adding the SSH Access application + the Tunnel + connector token | Off-LAN SSH admin path (`ssh [redacted historical Cloudflare team domain]`); supersedes any need for Tailscale break-glass once verified | - **Tailscale retain decision can be reaffirmed historically**: the cloudflare-dns handback confirmed no Cloudflare-side conflict with the @@ -398,7 +398,7 @@ later turn because they need family-cloudflare Pulumi commits first. ## Related -- Source: `/Users/verlyn13/Repos/local/cloudflare-dns/docs/handback-system-config-2026-05-13.md` at commit `b5b9460` +- Source: historical `cloudflare-dns` repository, source `docs/handback-system-config-2026-05-13.md` at commit `b5b9460` - [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) - the outbound request this answers - [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) - diff --git a/docs/device-admin/cloudflare-mesh-migration-design-2026-06-01.md b/docs/device-admin/cloudflare-mesh-migration-design-2026-06-01.md index 7356d7a..8756b87 100644 --- a/docs/device-admin/cloudflare-mesh-migration-design-2026-06-01.md +++ b/docs/device-admin/cloudflare-mesh-migration-design-2026-06-01.md @@ -31,7 +31,7 @@ authority. This **supersedes** the prior "holding, Gate 0 not passed" snapshot. **Current state (relayed):** - **Gate 0 — CLEARED.** Cloudflare Mesh (Beta) is available on the account; the - Zero Trust org **`homezerotrust`** is confirmed; the home-node LAN IP + Zero Trust org **`[redacted historical Cloudflare team identifier]`** is confirmed; the home-node LAN IP **`192.168.0.205`** is reserved. - **Addressing — DECIDED.** Mesh CGNAT range is **`100.96.0.0/12`** with **per-host single-overlay** (a host runs Tailscale **or** Mesh, never both; @@ -110,7 +110,7 @@ Gate 4. Proof is a real SSH/RDP probe, not a config readback. ### Draft A — `fedora-top-cloudflare-mesh-enroll` (likely Gate-2 pilot candidate) - **Why pilot:** Linux, non-critical, already hardened and system-config-managed. -- **Decided:** enroll fedora-top as a Mesh participant in `homezerotrust`; +- **Decided:** enroll fedora-top as a Mesh participant in `[redacted historical Cloudflare team identifier]`; reachable on its `100.96.0.0/12` Mesh IP. - **Steps (high-level):** install/verify Cloudflare One Client (`cloudflare-warp`; EPEL) — **note fedora-top is Fedora 44, outside Cloudflare's tested matrix @@ -155,7 +155,7 @@ Gate 4. Proof is a real SSH/RDP probe, not a config readback. | Gate | State | system-config's slice | |---|---|---| -| **Gate 0 — ELIGIBILITY** | **CLEARED 2026-06-02** (Mesh Beta available; ZT org `homezerotrust` confirmed; `.205` reserved) | none — owned by family-cloudflare + HomeNetOps | +| **Gate 0 — ELIGIBILITY** | **CLEARED 2026-06-02** (Mesh Beta available; ZT org `[redacted historical Cloudflare team identifier]` confirmed; `.205` reserved) | none — owned by family-cloudflare + HomeNetOps | | **Gate 1 — DESIGN** | landed (`main` v0.4.0) | this doc; PR only | | **Gate 2 — SINGLE-NODE PILOT** (operator Touch-ID) | **upstream IN PROGRESS** (HomeNetOps node + family-cloudflare profiles) | verify MacBook off-LAN reach to the pilot service over Mesh + default-deny enforcement + log visibility; fedora-top readiness if it is the pilot device. **Tailscale stays up.** | | **Gate 3 — PER-SURFACE** | pending Gate-2 | the three pre-staged drafts above, each with off-LAN AND break-glass proof; update `current-status.yaml` per surface | @@ -192,7 +192,7 @@ family-cloudflare authority; context only here. ## The Core Reframe **Cloudflare Mesh is the Cloudflare One Client (WARP) already on the operator -MacBook.** Not a new overlay — it reconfigures the existing `homezerotrust` +MacBook.** Not a new overlay — it reconfigures the existing `[redacted historical Cloudflare team identifier]` deployment to carry private mesh traffic, adds the single home node, and repoints SSH at Mesh IPs. All mesh traffic transits Cloudflare, so Gateway network policies, device posture, and identity checks apply to every connection (identity-aware diff --git a/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md b/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md index 9469f18..c9cd2dd 100644 --- a/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md +++ b/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md @@ -24,7 +24,7 @@ package, or CLI surface. Current-state note, added 2026-05-27: the original follow-up was aimed at the pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work now -belongs in `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, so +belongs in the owner-scoped `family-cloudflare` repository, so that repo must answer or supersede this rebaseline before any Windows cutover. ## Source diff --git a/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md b/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md index 4a3de79..d6d055f 100644 --- a/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md +++ b/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md @@ -27,8 +27,8 @@ device profiles unless a quoted command or source-era fact requires the legacy term. Current-state note, added 2026-05-27: Cloudflare authority has migrated from -the historical `cloudflare-dns` repo to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use the old +the historical `cloudflare-dns` repo to the owner-scoped +`family-cloudflare` repository. Use the old handbacks below for provenance only; current Cloudflare One Client, Access, Tunnel, and profile claims need `family-cloudflare` or live provider proof. @@ -61,7 +61,7 @@ Authority split: | Device / class | Cloudflare One Client | Tailscale | Current admin role | Overlay posture | |---|---|---|---|---| -| Operator MacBook `verlyns-mbp` | Enrolled in `homezerotrust`; one of the existing Cloudflare One Client fleet devices | Tailscale CLI/app present and locally inspectable; current proof shows route acceptance is not enabled, so travel private-route proof is still gated | Canonical admin origin; runs `system-config`, 1Password, SSH agent, agents, Windows App | Keep Cloudflare One Client as operator posture. For FU-23 travel, WARP remains primary DNS/policy/egress and Tailscale is private-route overlay only after route acceptance and off-LAN proof. Do not make another device an admin origin without a separate BC/DR packet. | +| Operator MacBook `verlyns-mbp` | Enrolled in `[redacted historical Cloudflare team identifier]`; one of the existing Cloudflare One Client fleet devices | Tailscale CLI/app present and locally inspectable; current proof shows route acceptance is not enabled, so travel private-route proof is still gated | Canonical admin origin; runs `system-config`, 1Password, SSH agent, agents, Windows App | Keep Cloudflare One Client as operator posture. For FU-23 travel, WARP remains primary DNS/policy/egress and Tailscale is private-route overlay only after route acceptance and off-LAN proof. Do not make another device an admin origin without a separate BC/DR packet. | | `fedora-top` | Not enrolled; target is Kids profile with `REDACTED-wyn-google-account` unless later Cloudflare design revises Linux multi-user handling | Installed and retained logged-out; no login, auth key, daemon restart, upgrade, or firewall passage authorized | LAN SSH target, administered from MacBook as `verlyn13` | Cloudflare is target off-LAN path; Tailscale is cold transition/break-glass only. | | `MAMAWORK` | Not enrolled; blocked on Windows multi-user Cloudflare One Client rebaseline | No Tailscale role evidenced | LAN SSH + LAN RDP target, administered from MacBook as `MAMAWORK\jeffr` | Future Cloudflare One Client enrollment must be per-Windows-user, not one machine-wide kid registration. | | `DESKTOP-2JJ3187` | Not enrolled; same Windows multi-user gate as MAMAWORK | No Tailscale role evidenced | LAN SSH + LAN RDP target, administered from MacBook as `DESKTOP-2JJ3187\jeffr` | Future Cloudflare One Client enrollment must follow shared-Windows profile separation. | @@ -318,7 +318,7 @@ Before treating any phone or tablet as recovery-capable, record answers to: - Which device is the recovery origin: iPhone, iPad, Android phone, or Pixel Private Space? -- Is Cloudflare One installed and enrolled to `homezerotrust` under the +- Is Cloudflare One installed and enrolled to `[redacted historical Cloudflare team identifier]` under the operator identity, not a kid or adult-work identity? - Can the device pass Cloudflare 2FA / Google OAuth / email OTP without the lost MacBook? diff --git a/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md b/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md index 8e11d34..90a4acb 100644 --- a/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md +++ b/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md @@ -36,8 +36,8 @@ and Traffic policies for Gateway policies. Command names such as `warp-cli` and the `cloudflare-warp` package name remain literal. Current-state note, added 2026-05-27: this design predates the migration from -`/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Keep the +the historical `cloudflare-dns` repository to the owner-scoped +`family-cloudflare` repository. Keep the design conclusions, but refresh Cloudflare-side evidence in `family-cloudflare` before authoring or applying any cutover packet. @@ -80,7 +80,7 @@ This design crosses three repos. The boundary is strict: |---|---|---|---| | Host hardening, host firewall, host package state, host SSH config, host daemon state | `system-config` (this repo) | All of it. | This document, packets, apply records. | | LAN routing, OPNsense rules, ISC DHCP, Unbound DNS, NAT, HAProxy frontends, WoL | HomeNetOps (`~/Repos/verlyn13/HomeNetOps`) | All LAN-layer state. | "We need " requests via the handback-format pattern; never reach in. | -| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need " requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. | +| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (owner-scoped `family-cloudflare` repository) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need " requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. | Implication: any statement in any subsequent packet of the form "the Cloudflare Access policy for `fedora-top` is N" must cite a @@ -189,7 +189,7 @@ routing layer. **Mechanism**: `cloudflared` runs as a service on `fedora-top` and maintains an outbound-initiated tunnel to Cloudflare's edge. The operator's MacBook (and any other admin device) joins the same -`homezerotrust` team via the Cloudflare One Client. A Cloudflare Access +`[redacted historical Cloudflare team identifier]` team via the Cloudflare One Client. A Cloudflare Access policy binds an `ssh.fedora-top.` hostname (or equivalent) to the operator's identity. SSH traffic flows MacBook -> Cloudflare One Client -> Cloudflare edge -> tunnel -> `fedora-top:22`. @@ -357,7 +357,7 @@ that supplies the following non-secret evidence: 1. **Current Cloudflare account and team structure**: - Account / team name(s) and their relation to Jefahnierocks. - - Whether the `homezerotrust` team is on the same account or a separate one. + - Whether the `[redacted historical Cloudflare team identifier]` team is on the same account or a separate one. - The current `family-cloudflare` repo path and the latest commit that should be cited. @@ -527,4 +527,4 @@ boundaries, nothing more. - [../secrets.md](../secrets.md) - HomeNetOps repo (external authority): `~/Repos/verlyn13/HomeNetOps` - `family-cloudflare` repo (external authority): - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` + owner-scoped `family-cloudflare` repository diff --git a/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md b/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md index 1c1ab23..f5adf08 100644 --- a/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md +++ b/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md @@ -50,8 +50,8 @@ device profile, and Traffic policies. Operator-relayed parent packets: -- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md` -- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md` +- owner-scoped orchestration source `orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md` +- owner-scoped orchestration source `orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md` System-config sources: @@ -73,7 +73,7 @@ System-config's input is limited to: - operator phone recovery proof steps only when explicitly reopened; current FU-23 travel scope keeps the phone WARP-only and non-admin; - browser/profile recovery proof steps; -- Cloudflare One Client health checks under `homezerotrust`; +- Cloudflare One Client health checks under `[redacted historical Cloudflare team identifier]`; - 1Password/account-recovery availability checks; - negative continuity checks so Kids, Headless, Default, and general Adults do not gain admin or broad LAN reachability; @@ -172,7 +172,7 @@ Expected pass shape: Expected pass shape: - The Cloudflare One Client is connected. -- The team/org is `homezerotrust`. +- The team/org is `[redacted historical Cloudflare team identifier]`. - The output does not show broad home-LAN CIDR reachability as the FU-23 primary proof path. - Any Gateway or Traffic policy weakness is recorded as a Cloudflare/device @@ -215,8 +215,8 @@ Record PASS/FAIL/date only. Do not commit screenshots. 1. From the travel MacBook's normal operator browser profile, open the Cloudflare dashboard. -2. Confirm the Nash Group / expected Cloudflare parent account is selectable. -3. Confirm the Cloudflare One dashboard / `homezerotrust` context can be +2. Confirm the expected parent-organization Cloudflare account is selectable. +3. Confirm the Cloudflare One dashboard / `[redacted historical Cloudflare team identifier]` context can be reached without changing any settings. 4. Record: @@ -251,7 +251,7 @@ reopens phone proof. Human steps: 1. Open Cloudflare One Agent on the operator phone. -2. Confirm it is enrolled to `homezerotrust` under the operator identity if it +2. Confirm it is enrolled to `[redacted historical Cloudflare team identifier]` under the operator identity if it is expected to be used for FU-23 recovery/test proof. 3. Open `https://help.teams.cloudflare.com/` from the phone browser. 4. Record Cloudflare One Agent and Gateway visible status as @@ -309,7 +309,7 @@ operator-supplied pass/fail records. Before any FU-23 apply is authorized elsewhere, system-config wants this checklist satisfied or explicitly waived by parent L0: -- [ ] MacBook Cloudflare One Client connected to `homezerotrust` under +- [ ] MacBook Cloudflare One Client connected to `[redacted historical Cloudflare team identifier]` under operator identity. - [ ] MacBook browser primary proof recorded. - [ ] Backup browser/profile proof recorded. diff --git a/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md b/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md index 94c1a68..fe3c3be 100644 --- a/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md +++ b/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md @@ -12,7 +12,7 @@ priority: high # Outbound Handback Request - `cloudflare-dns` - 2026-05-13 This document is a **request** from `system-config` to `cloudflare-dns` -(`/Users/verlyn13/Repos/local/cloudflare-dns`). It is not a directive +(historical `cloudflare-dns` repository). It is not a directive and does not authorize any change. It enumerates the non-secret evidence that `system-config` needs in order to author the Cloudflare Cloudflare One Client + `cloudflared` cutover packets for the household fleet. @@ -20,7 +20,7 @@ Cloudflare One Client + `cloudflared` cutover packets for the household fleet. Current-state note, added 2026-05-27: this request was answered by the pre-migration `cloudflare-dns` repo and remains historical provenance. Active Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; new packets +the owner-scoped `family-cloudflare` repository; new packets must refresh current claims there or against live provider proof. `family-cloudflare` is now the active authority for Cloudflare account and team @@ -81,7 +81,7 @@ fills the items below would be the simplest path. ```text - Cloudflare account/team name(s) and their relation to Jefahnierocks -- Whether the `homezerotrust` team is on the same Cloudflare account or a separate +- Whether the `[redacted historical Cloudflare team identifier]` team is on the same Cloudflare account or a separate org/account - The cloudflare-dns repo path and the latest commit that should be cited by system-config follow-up packets diff --git a/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md b/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md index cf9a3f7..b819b5c 100644 --- a/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md +++ b/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md @@ -24,7 +24,7 @@ unless the operator separately authorizes that work in the Current-state note, added 2026-05-27: this request was originally addressed to the pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; that repo +the owner-scoped `family-cloudflare` repository; that repo must answer or supersede this request before any Windows multi-user cutover. ## Why This Exists diff --git a/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md b/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md index 5d602b1..c86af9f 100644 --- a/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md +++ b/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md @@ -127,7 +127,7 @@ Cloudflare designer can finalize assignments. Cloudflare purposes. She uses devices; she does not administer the fleet. Jeff is the sole fleet administrator. - **Business-entity scope:** Litecky Editing Services is its - own business / org (separate entity, `~/Organizations/litecky-editing/`), + own business / org (separate entity under parent governance), but the operator confirms device management for Ahnie is routed through jefahnierocks for now. Ahnie's Cloudflare identity is jefahnierocks-managed via `REDACTED-ahnie-google-account`. @@ -170,12 +170,12 @@ state (current-status.yaml, system-wide section - **Identity providers configured in Cloudflare One:** Google OAuth + email OTP. -- **Cloudflare account name:** `The Nash Group`. -- **Cloudflare account ID:** `13eb584192d9cefb730fde0cfd271328`. -- **Team name:** `homezerotrust` (team domain - `homezerotrust.cloudflareaccess.com`). +- **Cloudflare account:** parent organization (provider label redacted). +- **Cloudflare account ID:** `[redacted historical Cloudflare account identifier]`. +- **Team name:** `[redacted historical Cloudflare team identifier]`. +- **Team domain:** `[redacted historical Cloudflare team domain]`. - **Account ownership scope (important):** the Cloudflare - account is at the **Nash Group parent level**, not the + account is at the **parent-organization level**, not the jefahnierocks-entity level. jefahnierocks devices, identities, and zones (including `jefahnierocks.com`) are tenants under this parent account. See §6 Scope Boundaries below. @@ -200,11 +200,11 @@ This means: - For the device-level cutovers this handback unblocks (Cloudflare One Client enrollment for fedora-top / MAMAWORK / DSJ; SSH Tunnel + Access for off-LAN admin), the design should work with - whatever operator identity Nash-Group IAM eventually settles + whatever operator identity parent-organization IAM eventually settles on, and not bake assumptions in. - Recommendation either way: design **as if** there will be a separate operator-tier profile (call it `Operator` for now) - distinct from `Adults`. If Nash-Group IAM later resolves + distinct from `Adults`. If parent-organization IAM later resolves Jeff's identity to plain `Adults`, the Operator profile can be merged or aliased. The reverse (designing only for Adults then having to split out later) is worse. @@ -348,8 +348,8 @@ SSH keys via Cloudflare Access posture + SSH Tunnel). enrolled + home-managed-network OR roaming with Cloudflare One Client + maybe US country), and what session length (8h recommended in prior partial handback). -- Define DNS surface: are these `ssh-.homezerotrust.cloudflareaccess.com` - hostnames, or a different domain pattern? +- Define DNS surface: should SSH endpoints use the redacted historical Cloudflare + team domain, or a different domain pattern? - Decide whether to use Cloudflare's `cloudflared access ssh` client wrapper or Access for Infrastructure (Application Connector + ssh-over-https) — the latter is newer Cloudflare @@ -606,11 +606,11 @@ clarification 2026-05-16: ### Account / ownership -- **Cloudflare account name:** `The Nash Group`. -- **Cloudflare account ID:** `13eb584192d9cefb730fde0cfd271328`. -- **Team name:** `homezerotrust`. -- **Team domain:** `homezerotrust.cloudflareaccess.com`. -- **Account scope:** Nash Group (parent). jefahnierocks devices +- **Cloudflare account:** parent organization (provider label redacted). +- **Cloudflare account ID:** `[redacted historical Cloudflare account identifier]`. +- **Team name:** `[redacted historical Cloudflare team identifier]`. +- **Team domain:** `[redacted historical Cloudflare team domain]`. +- **Account scope:** parent-organization level. jefahnierocks devices + zones (including `jefahnierocks.com`) are tenants under this parent account. See §6 Scope Boundaries. - **IaC:** Pulumi TypeScript in the `family-cloudflare` repo @@ -645,8 +645,8 @@ clarification 2026-05-16: - **Access apps:** None today. - **Tunnels:** None today. - Working naming candidates per fedora-top partial handback: - `tunnel-fedora-top`, `access-app-ssh-fedora-top`, - `ssh-fedora-top.homezerotrust.cloudflareaccess.com`. + `tunnel-fedora-top`, `access-app-ssh-fedora-top`, and an SSH hostname under + the redacted historical Cloudflare team domain. - **Gateway:** Active (DNS filtering on Cloudflare One Client-enrolled devices). Kids profile applies Cloudflare's recommended kids policies plus any family-cloudflare customizations. @@ -661,7 +661,7 @@ operator clarifications above, system-config recommends the designer evaluate **at least these candidate additions**: - **`Operator`** profile for Jeff (distinct from `Adults`). - Even if Nash-Group IAM eventually resolves Jeff's identity + Even if parent-organization IAM eventually resolves Jeff's identity to plain Adults, designing as if Operator-tier exists is cheaper than retrofitting. - **`Adults-Ahnie`** profile (kid-coexistence-aware adult, @@ -688,10 +688,10 @@ Cloudflare design touches: | Scope | Owner repo / entity | What it owns | What it does NOT own | |---|---|---|---| -| Parent governance | `the-nash-group` (parent entity) | Cloudflare account `The Nash Group` (`13eb584192d9cefb730fde0cfd271328`); cross-entity IAM and identity planning; standards; audit | Day-to-day device admin; per-family-member identity assignment; entity branding | -| Cloudflare IaC | `family-cloudflare` (managed by parent for all entities) | Pulumi TypeScript for the Nash Group Cloudflare account - Cloudflare One Client device profiles, Traffic policies, Access apps, Tunnels, DNS, managed networks, beacon registration | jefahnierocks-side device packets; operator-side Cloudflare One Client enrollment; identity-source decisions (those are IAM-planning scope) | -| Family device admin (this entity) | `jefahnierocks` (entity, `~/Organizations/jefahnierocks/`) | Device inventory and admin packets for family devices; per-device 1Password admin SSH keys; family identity-to-device mapping (Jeff / Ahnie / Axel / Wyn / Ila); fleet lifecycle | Cloudflare account or Pulumi state; Litecky-business resources; HomeNetOps LAN config; The Nash Group standards | -| Operator workspace + chezmoi orchestration | `system-config` (under jefahnierocks, this repo) | The operator MacBook config (chezmoi, mise, direnv, MCP, SSH client conf.d, 1P SSH agent integration); the device-admin packet ceremony (windows-terminal-admin-spec, packet-defect halt rule, etc.); operator-side Cloudflare One Client enrollment procedure | Cloudflare server-side; Pulumi state; Nash-Group IAM; what identities exist; LAN infrastructure | +| Parent governance | parent organization (identifier redacted) | Parent-organization Cloudflare account (account identifier redacted); cross-entity IAM and identity planning; standards; audit | Day-to-day device admin; per-family-member identity assignment; entity branding | +| Cloudflare IaC | `family-cloudflare` (managed by parent for all entities) | Pulumi TypeScript for the parent organization Cloudflare account - Cloudflare One Client device profiles, Traffic policies, Access apps, Tunnels, DNS, managed networks, beacon registration | jefahnierocks-side device packets; operator-side Cloudflare One Client enrollment; identity-source decisions (those are IAM-planning scope) | +| Family device admin (this entity) | `jefahnierocks` (entity; this public repository) | Device inventory and admin packets for family devices; per-device 1Password admin SSH keys; family identity-to-device mapping; fleet lifecycle | Cloudflare account or Pulumi state; business resources; HomeNetOps LAN config; parent-organization standards | +| Operator workspace + chezmoi orchestration | `system-config` (under jefahnierocks, this repo) | The operator MacBook config (chezmoi, mise, direnv, MCP, SSH client conf.d, 1P SSH agent integration); the device-admin packet ceremony (windows-terminal-admin-spec, packet-defect halt rule, etc.); operator-side Cloudflare One Client enrollment procedure | Cloudflare server-side; Pulumi state; parent-organization IAM; what identities exist; LAN infrastructure | **Implications for the Cloudflare designer:** @@ -704,12 +704,12 @@ Cloudflare design touches: `desktop-2jj3187-warp-enrollment-cutover-packet`, `fedora-top-warp-enrollment-cutover-packet`), each gated on family-cloudflare answering this handback. -- Operator Cloudflare admin identity is a Nash-Group IAM +- Operator Cloudflare admin identity is a parent-organization IAM decision (not jefahnierocks scope). Design with that separation in mind. - Litecky Editing Services (Ahnie's business) is a separate - entity under Nash Group with its own repo - (`~/Organizations/litecky-editing/`). For now, Ahnie's + entity under parent organization with its own repo + (owner-scoped repository). For now, Ahnie's Cloudflare identity is jefahnierocks-managed (`REDACTED-ahnie-google-account`) because device management is routed through jefahnierocks. If Litecky-entity Cloudflare resources are eventually needed @@ -793,7 +793,7 @@ that answers, at minimum: policy each, what's the assignment rule. 2. **Jeff's profile placement** — Adults or a new `Operator` / `Admin` profile? Note that the actual Cloudflare admin - identity for Jeff is a **Nash-Group IAM decision** (not + identity for Jeff is a **parent-organization IAM decision** (not jefahnierocks); recommend designing as if a separate Operator tier exists, then aliasing if IAM-planning collapses it back to Adults. @@ -847,16 +847,16 @@ that answers, at minimum: - Wyn: `REDACTED-wyn-google-account`. - Ila: `REDACTED-ila-google-account`. - **Outstanding identity decision is Nash-Group scope, not + **Outstanding identity decision is parent-organization scope, not jefahnierocks:** Jeff's actual Cloudflare admin identity (Happy Patterns work email vs. personal Gmail vs. some - other) is part of broader IAM planning at the Nash Group - parent. family-cloudflare can either (a) wait for Nash-Group + other) is part of broader IAM planning at the parent-organization + level. family-cloudflare can either (a) wait for parent-organization IAM to resolve before finalizing operator-tier Access policies, or (b) design with a placeholder operator identity that can be re-mapped when IAM-planning lands. Operator preference: do not block jefahnierocks device - cutovers on Nash-Group IAM planning; design with a + cutovers on parent-organization IAM planning; design with a placeholder. ### Operator-roaming policy @@ -953,7 +953,7 @@ operator's admin capability — fully or partially. | **MacBook physical loss / theft (non-compromise)** | Same as death; but with credential rotation as precaution | Same as death; plus pre-emptive 1P session invalidation + GitHub token rotation + Cloudflare session invalidation | | **MacBook stolen, awake, unlocked, 1P agent unlocked** | Catastrophic: everything reachable from MacBook is in adversarial hands until the operator-side blast radius is contained | Emergency session-invalidation from any other 1P-capable device; rotate every per-device admin SSH key (the agent could still be unlocked); rotate every API token in 1P that was last used recently | | **1Password account compromised (separate from MacBook)** | Every per-device admin SSH key is exposed; every API token in `Dev` vault is exposed | Full 1P recovery flow + Cloudflare/GitHub/Hetzner/every-provider rotation. Worse than MacBook theft. | -| **Cloudflare account compromised** | device profiles can be re-pointed; Access policies can be modified; Gateway can be turned off; Tunnels can be created against any host; `jefahnierocks.com` DNS can be rewritten | Nash-Group escalation; Cloudflare support recovery; potentially zone re-transfer | +| **Cloudflare account compromised** | device profiles can be re-pointed; Access policies can be modified; Gateway can be turned off; Tunnels can be created against any host; the parent organization's primary domain can be rewritten | parent-organization escalation; Cloudflare support recovery; potentially zone re-transfer | | **Cloudflare account suspended (billing/TOS)** | All Cloudflare One Client + Access + Tunnel + Gateway features stop. `jefahnierocks.com` DNS stops. Family internet may stop (depending on DNS dependency). | Resolve with Cloudflare; meanwhile fall back to LAN-direct admin (no off-LAN admin available) | | **Google account suspended / lost (jeffrey@happy-patterns.com)** | Loss of Cloudflare OAuth login (sign in as that identity). Loss of Workspace email. Possible cascade to GitHub if linked. | Google recovery flow. Email OTP fallback for Cloudflare (if configured per-profile). | | **GitHub access lost (token rotation, account lock)** | system-config repo + every other repo become inaccessible from operator | GitHub recovery flow; 1P-stored GitHub PAT recovery | @@ -961,7 +961,7 @@ operator's admin capability — fully or partially. | **Hetzner outage** | If cloudflared is on Hetzner only, all off-LAN admin breaks. If LAN connector exists too, off-LAN admin still works. | Wait for Hetzner. | | **Home LAN power outage** | All on-LAN admin targets unreachable; Synology beacon down (no managed-network detection). WoL on UPS-fed devices could still wake them. | UPS for critical gear (Synology, OPNsense). Off-LAN admin not helpful unless devices come up on a battery-backed switch. | | **Synology beacon cert/disk failure** | Cloudflare managed-network detection fails (devices think they're off-LAN even when home) | Re-deploy beacon (10-year cert is static; can be copied from backup). family-cloudflare Pulumi state should carry the fingerprint pin. | -| **Operator (Jeff) incapacitated / unreachable** | No admin can happen until Jeff recovers or successor is empowered. No documented successor today (see §8.5). | Nash-Group governance; needs pre-planning. | +| **Operator (Jeff) incapacitated / unreachable** | No admin can happen until Jeff recovers or successor is empowered. No documented successor today (see §8.5). | parent-organization governance; needs pre-planning. | ### 8.3 MacBook loss / theft / death scenarios (three flavors) @@ -1040,7 +1040,7 @@ Inputs the operator needs **to even start that flow**: | 1Password Secret Key (account-bind) | 1P emergency kit PDF | Must be stored offline (printed in safe, encrypted USB, etc.) | | Apple ID password | Operator brain / iCloud Keychain | If iCloud Keychain was on the lost MacBook, Apple recovery flow | | GitHub recovery codes / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator | -| Cloudflare account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator. Note Nash-Group scope. | +| Cloudflare account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator. Note parent-organization scope. | | Hetzner account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator | | Domain registrar (where `jefahnierocks.com` and `happy-patterns.com` are registered) recovery | Should be in 1P + offline | Currently: TBD-operator | @@ -1064,13 +1064,13 @@ enrollment + 2FA), not require persistent device fingerprinting. Jeff is sole admin. If Jeff is unavailable (vacation off-grid, incapacitated, unreachable for weeks, deceased), no one can -currently administer the family fleet. The Nash Group parent +currently administer the family fleet. The parent-organization scope owns this concern (it's an IAM-succession question beyond jefahnierocks), but jefahnierocks records it here so the Cloudflare design accounts for it: - **Who is Jeff's emergency successor?** TBD-operator. Likely - a Nash-Group-trusted party. + a parent-organization-trusted party. - **What does the successor need access to?** At minimum: - 1P vault `Dev` (read access; admin would need write). - Cloudflare account (admin tier). @@ -1181,7 +1181,7 @@ architect them out: should encourage automated `cloudflared` updates on whichever host runs it. system-config can package this. - **Operator forgets which Cloudflare account is which.** When - Nash-Group manages multiple entities' Cloudflare resources, + parent-organization manages multiple entities' Cloudflare resources, the operator working on jefahnierocks devices can't accidentally mutate happy-patterns / litecky resources. family-cloudflare Pulumi state per-entity scoping helps; @@ -1302,9 +1302,9 @@ but family-cloudflare will need these to finalize) - [ ] **Jeff's Cloudflare admin identity** — Happy Patterns email, personal Gmail, or something else. **This is a - Nash-Group IAM-planning decision, not a jefahnierocks + parent-organization IAM-planning decision, not a jefahnierocks decision.** family-cloudflare should design with a placeholder - operator identity and re-map when Nash-Group IAM-planning + operator identity and re-map when parent-organization IAM-planning resolves. - [ ] **Hetzner inventory** — count of servers, role(s), public IP(s). Needed only if the designer wants to recommend Option diff --git a/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md b/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md index 89f0ab9..0eddb20 100644 --- a/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md +++ b/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md @@ -23,8 +23,8 @@ DHCP, WARP, Tailscale, 1Password, or host change is performed by this ingest. Current-state note, added 2026-05-27: this ingest predates the migration from -`/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Treat +the historical `cloudflare-dns` repository to the owner-scoped +`family-cloudflare` repository. Treat Cloudflare facts here as historical/advisory only; current Cloudflare authority is `family-cloudflare` or live provider proof. @@ -32,7 +32,7 @@ is `family-cloudflare` or live provider proof. | Field | Value | |---|---| -| Source repo | `/Users/verlyn13/Organizations/the-nash-group/hetzner` | +| Source repo | owner-scoped `hetzner` repository | | Source report | `docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md` | | Source commit cited | `009c091bc63556e6fb43503bf70aee97a269ea82` (`docs: leave-clean status refresh post Phase 2 and post-transfer truth alignment (#23)`) | | Source inspection mode | repo-only at Hetzner-repo authoring time; no live server, dashboard, Cloudflare API, or 1Password read was performed for that report | @@ -160,7 +160,7 @@ repos. ## Related -- Hetzner repo source report (`/Users/verlyn13/Organizations/the-nash-group/hetzner/docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md`) +- Hetzner repo source report (owner-scoped `hetzner` repository, source `docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md`) - [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) - the historical outbound request. - [fedora-top-remote-admin-routing-design-2026-05-13.md](./fedora-top-remote-admin-routing-design-2026-05-13.md) - diff --git a/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md b/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md index 02aa2c1..ca17db1 100644 --- a/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md +++ b/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md @@ -99,11 +99,11 @@ HomeNetOps sources: Family-cloudflare sources: -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-overlay-coexistence.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/design-surfaces.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/managed-network-tls-beacon.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/architecture.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` +- owner-scoped `family-cloudflare` repository, source `docs/warp-overlay-coexistence.md` +- owner-scoped `family-cloudflare` repository, source `docs/design-surfaces.md` +- owner-scoped `family-cloudflare` repository, source `docs/managed-network-tls-beacon.md` +- owner-scoped `family-cloudflare` repository, source `docs/architecture.md` +- owner-scoped `family-cloudflare` repository, source `infrastructure/pulumi/policy-inputs.yaml` HomeNetOps stand-down sources: @@ -131,7 +131,7 @@ dig @1.1.1.1 A ### Cloudflare One Client / WARP -The MacBook is connected to `homezerotrust` and healthy. WARP is in +The MacBook is connected to `[redacted historical Cloudflare team identifier]` and healthy. WARP is in `WarpWithDnsOverHttps` mode with WireGuard tunnel protocol. The Operator profile is exclude-mode and includes at least: @@ -323,7 +323,7 @@ TAILSCALE_BE_CLI=1 /usr/local/bin/tailscale set --accept-routes=true --accept-dn Expected laptop invariants: -- WARP connected to `homezerotrust`; +- WARP connected to `[redacted historical Cloudflare team identifier]`; - WARP remains DNS/policy/egress plane; - Tailscale accepts private routes only; - no Tailscale DNS ownership; diff --git a/docs/device-admin/onboarding-2026-05-12.md b/docs/device-admin/onboarding-2026-05-12.md index f16cb07..5ed8b14 100644 --- a/docs/device-admin/onboarding-2026-05-12.md +++ b/docs/device-admin/onboarding-2026-05-12.md @@ -28,8 +28,8 @@ Gateway policy where older packets used them; new interpretation should map those to Cloudflare One Client, device profile, and Traffic policies. Current-state note, added 2026-05-27: Cloudflare control-plane authority has -migrated from `/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Historical +migrated from the historical `cloudflare-dns` repository to the owner-scoped +`family-cloudflare` repository. Historical `cloudflare-dns` requests and ingests remain provenance; current Cloudflare blockers and proof requests should route to `family-cloudflare`. @@ -198,10 +198,10 @@ Use these documents when starting an agent directly on the target device: | DESKTOP-2JJ3187 | [desktop-2jj3187-rca-follow-up-session-2026-05-16.md](./desktop-2jj3187-rca-follow-up-session-2026-05-16.md), [desktop-2jj3187-service-sid-comparison-apply-2026-05-16.md](./desktop-2jj3187-service-sid-comparison-apply-2026-05-16.md), [desktop-2jj3187-lsa-privilege-inspection-apply-2026-05-16.md](./desktop-2jj3187-lsa-privilege-inspection-apply-2026-05-16.md), [desktop-2jj3187-openssh-runtime-shape-inspection-apply-2026-05-16.md](./desktop-2jj3187-openssh-runtime-shape-inspection-apply-2026-05-16.md) | Concise RCA follow-up plus H1/H2/runtime-shape apply records. Refutes missing local SAM `sshd` user, current CBS install failure, host-key ACL, Match-block indent, service SID type, and static LSA selected-rights as differentiators. Current leading differential: DESKTOP service-side OpenSSH `9.5.0.1` vs MAMAWORK `9.5.5.1`; next packet is corrected read-only service-mode static differential. | | MAMAWORK mini-PC | [windows-pc-mamawork.md](./windows-pc-mamawork.md) | Master record for the second household Windows host (`MAMAWORK`, AZW SER mini-PC, Windows 11 Pro 25H2). Ingests the elevated read-only intake captured 2026-05-13 by `MAMAWORK\jeffr` in PowerShell 7.6.1. LAN SSH from the MacBook is now operational as `jeffr@mamawork.home.arpa` using the 1Password-backed key `SHA256:qilvkR7/...`; LAN RDP also works but is secondary because it conflicts with the active console session. WinRM/PSRemoting disabled; BitLocker/Secure Boot off; PIA fully removed. Status: partially managed, not yet hardened. | | MAMAWORK mini-PC | [handoff-mamawork.md](./handoff-mamawork.md) | Follow-up handoff that captures 16 operator questions (SSH key continuity from fedora-top, family Microsoft Account mapping, `DadAdmin` replacement, `CodexSandboxOnline`/`CodexSandboxOffline`/`WsiAccount` identities, Defender exclusion subjects, BitLocker / Secure Boot stance, backup plan, etc.) and lists the future approval-gated packets that each question gates. | -| Outbound to cloudflare-dns | [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) | Historical request to `/Users/verlyn13/Repos/local/cloudflare-dns` for org-wide Cloudflare One / Cloudflare One Client / Access / Tunnel posture and per-device profile recommendations. Current claims must be refreshed in `family-cloudflare`. Non-secret only; no live Cloudflare change requested. | +| Outbound to cloudflare-dns | [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) | Historical request to the `cloudflare-dns` repository for org-wide Cloudflare One / Cloudflare One Client / Access / Tunnel posture and per-device profile recommendations. Current claims must be refreshed in `family-cloudflare`. Non-secret only; no live Cloudflare change requested. | | Outbound to HomeNetOps | [handback-request-homenetops-2026-05-13.md](./handback-request-homenetops-2026-05-13.md) | Two-item request to `~/Repos/verlyn13/HomeNetOps`: (1) posture confirmation for fedora-top (no new rule requested); (2) static-DHCP reservation for MAMAWORK Ethernet MAC `B0-41-6F-0E-B7-B6` -> `192.168.0.101` plus Unbound host override `mamawork.home.arpa`. Mirrors the 2026-05-13 fedora-top pattern. Non-secret only. **Answered 2026-05-14** - see [mamawork-homenetops-lan-identity-2026-05-14.md](./mamawork-homenetops-lan-identity-2026-05-14.md). | | MAMAWORK mini-PC | [mamawork-homenetops-lan-identity-2026-05-14.md](./mamawork-homenetops-lan-identity-2026-05-14.md) | Ingest of the HomeNetOps PASS hand-back for MAMAWORK. OPNsense static DHCP reservation bound, Unbound override `mamawork.home.arpa -> 192.168.0.101`, LAN/igc1 ARP confirms IP-to-MAC, `dig` PASS from LAN resolver. The earlier TCP/22 timeout was Windows-side and has since been resolved for the MacBook admin lane. ARP `permanent=false` because MAMAWORK is host-static; switching to DHCP would activate ISC static-ARP defense (optional follow-up packet). | -| Hetzner (advisory) | [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) | Advisory-only ingest of `/Users/verlyn13/Organizations/the-nash-group/hetzner` commit `009c091`. Hetzner brokers Cloudflare Tunnel ingress for hosted apps (Infisical, Postal Web, runpod-review-webui); it is NOT a household device control plane. Encodes the decision to NOT route household device admin through Hetzner; preferred target remains Cloudflare One Client / Access via `family-cloudflare`; Tailscale stays transition/break-glass. Does not satisfy current `family-cloudflare` proof needs. | +| Hetzner (advisory) | [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) | Advisory-only ingest of owner-scoped `hetzner` repository commit `009c091`. Hetzner brokers Cloudflare Tunnel ingress for hosted apps (Infisical, Postal Web, runpod-review-webui); it is NOT a household device control plane. Encodes the decision to NOT route household device admin through Hetzner; preferred target remains Cloudflare One Client / Access via `family-cloudflare`; Tailscale stays transition/break-glass. Does not satisfy current `family-cloudflare` proof needs. | | Fedora 44 laptop | [fedora-top-admin-backup-ssh-key-strategy-packet-2026-05-14.md](./fedora-top-admin-backup-ssh-key-strategy-packet-2026-05-14.md) | Prepared. Adds one additional `verlyn13` ED25519 admin public key to `fedora-top` `/home/verlyn13/.ssh/authorized_keys`, with the private half held only in 1Password (Dev vault on my.1password.com) and served via the 1Password SSH agent on a backup operator device. Keeps `AllowUsers verlyn13`. Keeps `PasswordAuthentication no`. Does not add any other admin user. Does not reuse the legacy MAMAWORK `DadAdmin_WinNet` key. Snapshot-backed rollback. Closes the single-MacBook dependency for fedora-top remote administration. | | MAMAWORK mini-PC | [mamawork-ssh-investigation-packet-2026-05-14.md](./mamawork-ssh-investigation-packet-2026-05-14.md), [mamawork-inbound-tcp-blackhole-remediation-apply-2026-05-14.md](./mamawork-inbound-tcp-blackhole-remediation-apply-2026-05-14.md), [mamawork-sshd-admin-match-block-apply-2026-05-14.md](./mamawork-sshd-admin-match-block-apply-2026-05-14.md) | SSH investigation/remediation chain. Scoped investigation found Windows network-identity drift; remediation restored LAN TCP/22 and TCP/3389 reachability from the MacBook. Admin auth still failed until the sshd admin Match block packet restored `AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys` for local Administrators. MacBook real-auth proof now returns `MamaWork` / `mamawork\jeffr`. | | MAMAWORK mini-PC | [mamawork-switch-to-dhcp-source-of-truth-packet-2026-05-14.md](./mamawork-switch-to-dhcp-source-of-truth-packet-2026-05-14.md) | Prepared, optional. Switches the MAMAWORK wired adapter from host-side static IP (`192.168.0.101` manual) to DHCP so the existing OPNsense reservation owns the address and ISC static-ARP defense can activate (currently `permanent=false`). Brief 2-10 second reconnect window. Intentionally separate from the SSH investigation packet so connectivity changes are not bundled with debugging. | diff --git a/docs/git-identity.md b/docs/git-identity.md index 819f620..083c4d7 100644 --- a/docs/git-identity.md +++ b/docs/git-identity.md @@ -112,9 +112,19 @@ Failure receipts contain only a repository-relative path and rule identifier. If the identifier occurs in the path itself, the path is redacted. No matched text, identity, hash, or length is emitted. Narrow, rule-specific exceptions live in [`policies/public-privacy.json`](../policies/public-privacy.json) for -truthful historical evidence, byte-pinned sources, and coordinated runtime -identifiers. An exception is classification, not permission to add new active -authority or executable use. +byte-pinned sources and coordinated runtime identifiers. Historical provenance +is not a privacy exception: a dated filename, superseded plan, or immutable +evidence record does not suppress a rule for the whole file. + +Public historical records preserve claims, not incidental workstation +locators. Prefer a semantic owner role; otherwise record the logical repository, +source document, immutable commit OID, and evidence date. Use an explicit +redaction marker when the existence of a private value matters. Exact private +identifiers require a separately reviewed, rule-specific non-historical +exception; personal contact or credential-like material is not retained on +historical grounds. Later current-state notes and commands remain active prose. +Runtime/structural identifiers and byte-pinned material are routed to their own +classifications rather than mislabeled as history. ## Enforcement model diff --git a/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md b/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md index 2cc4092..90edcef 100644 --- a/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md +++ b/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md @@ -207,8 +207,8 @@ not change the broker's other contracts: The identity transition is also part of the baseline. The interim operator OAuth identity is `REDACTED-operator-google-account` (Option B); the Phase C -target identity is `guardian@thenash.group`, with the Cloudflare account email -migration target date of 2026-07-15, per parent identifier +target is the parent-organization administrator identity. The Cloudflare account +email migration target date is 2026-07-15, per parent identifier `OPERATOR-CLOUDFLARE-ADMIN-IDENTITY-DECISION-2026-05-16.md`. The broker's typed-operation and lease-and-ledger contract is identity-agnostic, but a future broker implementation should pin the current operator identity in audit diff --git a/docs/restart-handoff-2026-08-08.md b/docs/restart-handoff-2026-08-08.md index b00b211..7b9dc71 100644 --- a/docs/restart-handoff-2026-08-08.md +++ b/docs/restart-handoff-2026-08-08.md @@ -113,7 +113,7 @@ three real clones: | Clone path | Verified live fact | | --- | --- | -| `/Users/verlyn13/Organizations/the-nash-group-github-profile` | Origin uses `github.com`, while the registry expects `github.com-nash-group`; local status already had 3 entries. The doctor prints this same clone as `parent-org/.github` in the remote check and `The-Nash-Group/.github` in the config-drift check. | +| [redacted historical checkout root] | Origin used the default GitHub host rather than the registered parent-organization SSH lane; local status already contained three entries. The doctor rendered two different owner spellings for this same clone, confirming registry/config drift without republishing either private spelling. | | `/Users/verlyn13/Organizations/happy-patterns/apps/happy-patterns-org.github.io` | Clean worktree; origin uses `github.com`, while the registry expects `github.com-happy-patterns`; email/signing/host configuration also differs from the registered lane. | | `/Users/verlyn13/Organizations/happy-patterns/apps/scopecam` | Clean worktree on `development`; origin uses `github.com`, while the registry expects `github.com-happy-patterns`; email/signing/host configuration also differs from the registered lane. | diff --git a/policies/public-privacy.json b/policies/public-privacy.json index 5a7fbfb..6754a74 100644 --- a/policies/public-privacy.json +++ b/policies/public-privacy.json @@ -20,33 +20,6 @@ ".edu" ], "classifications": [ - { - "glob": "docs/device-admin/*-2026-*.md", - "class": "historical", - "exempt_rules": [ - "external-organization-path", - "private-dictionary" - ], - "reason": "Dated operational provenance; personal-email detection remains active." - }, - { - "glob": "docs/host-capability-substrate/2026-*.md", - "class": "historical", - "exempt_rules": [ - "external-organization-path", - "private-dictionary" - ], - "reason": "Dated design and operational evidence; personal-email detection remains active." - }, - { - "glob": "docs/restart-handoff-*.md", - "class": "historical", - "exempt_rules": [ - "external-organization-path", - "private-dictionary" - ], - "reason": "Dated workstation evidence; current policy lives elsewhere." - }, { "glob": "docs/iterm2-*.md", "class": "runtime-identifier", diff --git a/scripts/validate_public_privacy.py b/scripts/validate_public_privacy.py index 405d2b4..65e53b1 100755 --- a/scripts/validate_public_privacy.py +++ b/scripts/validate_public_privacy.py @@ -19,6 +19,7 @@ RULE_ORGANIZATION_PATH = "external-organization-path" RULE_PERSONAL_EMAIL = "personal-email" RULE_PRIVATE_DICTIONARY = "private-dictionary" +CLASS_HISTORICAL = "historical" RULES = { RULE_ORGANIZATION_PATH, RULE_PERSONAL_EMAIL, @@ -43,6 +44,7 @@ class PrivacyError(RuntimeError): @dataclass(frozen=True) class Classification: glob: str + classification_class: str exempt_rules: frozenset[str] @@ -55,7 +57,9 @@ class Policy: def is_exempt(self, path: str, rule: str) -> bool: return any( - rule in item.exempt_rules and fnmatch.fnmatchcase(path, item.glob) + item.classification_class != CLASS_HISTORICAL + and rule in item.exempt_rules + and fnmatch.fnmatchcase(path, item.glob) for item in self.classifications ) @@ -120,13 +124,22 @@ def load_policy(path: Path) -> Policy: for field in ("glob", "class", "reason") ): raise PrivacyError("invalid-policy:classification-value") + classification_class = item["class"] exempt_rules = frozenset( _string_list(item["exempt_rules"], "classification.exempt_rules") ) - if not exempt_rules or not exempt_rules <= RULES: + if not exempt_rules <= RULES: + raise PrivacyError("invalid-policy:classification-rule") + if classification_class == CLASS_HISTORICAL and exempt_rules: + raise PrivacyError("invalid-policy:historical-exemption") + if classification_class != CLASS_HISTORICAL and not exempt_rules: raise PrivacyError("invalid-policy:classification-rule") classifications.append( - Classification(glob=item["glob"], exempt_rules=exempt_rules) + Classification( + glob=item["glob"], + classification_class=classification_class, + exempt_rules=exempt_rules, + ) ) normalized_roots = frozenset(value.casefold() for value in public_roots) diff --git a/tests/public-privacy/run.sh b/tests/public-privacy/run.sh index 32030a6..c042cae 100755 --- a/tests/public-privacy/run.sh +++ b/tests/public-privacy/run.sh @@ -23,6 +23,12 @@ run_validator() { --policy "$FIXTURE_ROOT/repo/policy.json" "$@" } +run_validator_with_policy() { + local policy="$1" + shift + "$VALIDATOR" --repo "$FIXTURE_ROOT/repo" --policy "$policy" "$@" +} + expect_pass() { local name="$1" shift @@ -66,8 +72,8 @@ cat >"$FIXTURE_ROOT/repo/policy.json" <<'JSON' { "glob": "docs/history/**", "class": "historical", - "exempt_rules": ["external-organization-path", "private-dictionary"], - "reason": "Synthetic dated provenance." + "exempt_rules": [], + "reason": "Synthetic dated provenance with no privacy exemption." }, { "glob": "runtime/**", @@ -107,13 +113,23 @@ expect_fail_private "a personal-domain suffix fails value-blindly" \ "$academic_email" "docs/academic-email.md" "personal-email" run_validator rm "$FIXTURE_ROOT/repo/docs/academic-email.md" -printf '/%s/%s/%s/%s/archive\n' \ - "Users" "example" "Organizations" "$private_root" \ +printf '%s\n%s\n' \ + '[redacted historical checkout root]' \ + 'Source: owner-scoped control-plane repository; document docs/report.md; commit 0123abc' \ >"$FIXTURE_ROOT/repo/docs/history/record.md" -expect_pass "historical paths remain explicitly classified" run_validator +expect_pass "redacted and logical historical provenance passes" run_validator + +printf 'Current-state note: /%s/%s/%s/%s/new-work\n' \ + "Users" "example" "Organizations" "$private_root" \ + >>"$FIXTURE_ROOT/repo/docs/history/record.md" +expect_fail_private "a new private path in historical prose is not exempt" \ + "$private_root" "docs/history/record.md" "external-organization-path" \ + run_validator +sed -i.bak '$d' "$FIXTURE_ROOT/repo/docs/history/record.md" +rm "$FIXTURE_ROOT/repo/docs/history/record.md.bak" printf '%s\n' "$private_email" >>"$FIXTURE_ROOT/repo/docs/history/record.md" -expect_fail_private "historical classification does not exempt personal email" \ +expect_fail_private "historical prose does not exempt personal email" \ "$private_email" "docs/history/record.md" "personal-email" run_validator sed -i.bak '$d' "$FIXTURE_ROOT/repo/docs/history/record.md" rm "$FIXTURE_ROOT/repo/docs/history/record.md.bak" @@ -137,14 +153,54 @@ rm -r "$FIXTURE_ROOT/repo/docs/$dictionary_value" printf '%s\n' "$private_email" \ >"$FIXTURE_ROOT/repo/docs/history/$dictionary_value.md" -expect_fail_private "an exempt private path stays redacted for another rule" \ +expect_fail_private "a private path stays redacted when another rule also fails" \ "$dictionary_value" "" "personal-email" \ run_validator --private-dictionary "$FIXTURE_ROOT/private-dictionary.txt" rm "$FIXTURE_ROOT/repo/docs/history/$dictionary_value.md" printf '%s\n' "$dictionary_value" >>"$FIXTURE_ROOT/repo/docs/history/record.md" -expect_pass "private dictionary respects the historical classification" \ +expect_fail_private "historical prose does not exempt private dictionary terms" \ + "$dictionary_value" "docs/history/record.md" "private-dictionary" \ + run_validator --private-dictionary "$FIXTURE_ROOT/private-dictionary.txt" +sed -i.bak '$d' "$FIXTURE_ROOT/repo/docs/history/record.md" +rm "$FIXTURE_ROOT/repo/docs/history/record.md.bak" + +printf '%s\n' "$dictionary_value" >"$FIXTURE_ROOT/repo/runtime/key.md" +expect_pass "runtime classification retains its narrow dictionary exemption" \ run_validator --private-dictionary "$FIXTURE_ROOT/private-dictionary.txt" +rm "$FIXTURE_ROOT/repo/runtime/key.md" + +cat >"$FIXTURE_ROOT/repo/invalid-historical-policy.json" <<'JSON' +{ + "version": 1, + "public_organization_roots": ["public-org"], + "personal_email_domains": ["mailbox.example"], + "personal_email_suffixes": [".school"], + "classifications": [ + { + "glob": "docs/history/**", + "class": "historical", + "exempt_rules": ["external-organization-path"], + "reason": "An invalid whole-file historical exemption." + } + ] +} +JSON +if run_validator_with_policy \ + "$FIXTURE_ROOT/repo/invalid-historical-policy.json" \ + >"$FIXTURE_ROOT/stdout" 2>"$FIXTURE_ROOT/stderr"; then + fail "historical classifications cannot suppress privacy rules" +fi +if rg -F "$private_root" "$FIXTURE_ROOT/stdout" \ + "$FIXTURE_ROOT/stderr" >/dev/null; then + fail "an invalid historical policy error leaked matched material" +fi +if ! rg -F 'public privacy: ERROR [invalid-policy:historical-exemption]' \ + "$FIXTURE_ROOT/stderr" >/dev/null; then + fail "an invalid historical policy omitted its value-blind error" +fi +pass "historical classifications cannot suppress privacy rules" +rm "$FIXTURE_ROOT/repo/invalid-historical-policy.json" staged_value="staged-private-root" printf '/%s/%s/%s/%s/staged\n' \