kaizen-agentic/engagements/pilots/eng-coulomb-railiance01-ho-001/access-plan.md
tegwick 06037b0486
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
ci / test (push) Failing after 9s
CI Smoke / container-smoke (push) Successful in 4s
docs: UFW k3s API admin allowlist procedure for host-operator
Add reusable protocol, wire it in ROLE.yaml, and document the current
railiance01 allowlist plus quick commands in the pilot access-plan.
2026-07-16 14:04:44 +02:00

3.5 KiB

Access plan — eng-coulomb-railiance01-ho-001

Target: host railiance01 Classes requested: host_observe, privileged_ops (gated) Secrets: never stored in this tree

Intended path

Step Action Owner
1 Inventory / facts from railiance-hosts (read-only) operator
2 SSH as workstation user (tegwick) or cert via ops-warden operator
3 Tunnel if needed (ops-bridge, e.g. state-hub-railiance01) operator
4 Observe session: non-destructive health/load/os checks host-operator agent
5 Privileged ops only after human approval recorded in vault human + agent

Working path (verified 2026-07-16)

Item Detail
SSH Host alias railiance01 in ~/.ssh/config
HostName 92.205.62.239
User tegwick
IdentityFile ~/.ssh/id_custodian_agent (also works with id_ops in this environment)
Verify command ssh -o BatchMode=yes railiance01 'hostname; uptime'
Inventory railiance-hosts/inventory/servers.yaml
Bridge state-hub-railiance01, issue-core-railiance01, state-hub-primary connected (static-key)
Sudo passwordless sudo -n available for read-only admin inspect (k3s, ufw status, needrestart)

Credential routing

  • SSH certificates → ops-warden when using cert_command actors
  • This pilot used existing workstation SSH key path (static key) for observe
  • API keys / DB passwords → OpenBao via warden route (not this agent)
  • Do not message ops-warden for secret values

UFW k3s API admin allowlist (6443)

Policy (since 2026-07-16 remediation): port 6443/tcp is not open to the world. Remote k3s API / kubectl against the public IP works only from allowlisted admin public IPs. SSH (22) remains open Anywhere.

Full procedure: roles/host-operator/protocols/ufw-admin-allowlist.md

Current allowlist (update when changing UFW)

Public IP Label Added Notes
89.244.90.246 k3s-api-operator-current 2026-07-16 Session IP during P4 remediation
85.132.220.102 k3s-api-operator-hist 2026-07-16 Historical login IP

Quick commands (railiance01)

# Discover your public IP (on the admin laptop)
curl -4 -s ifconfig.me; echo

# List rules
ssh railiance01 'sudo ufw status numbered verbose'

# Add admin
ssh railiance01 "sudo ufw allow from <PUBLIC_IP> to any port 6443 proto tcp comment 'k3s-api-admin-<label>'"

# Remove: use rule number from status numbered
ssh railiance01 'sudo ufw delete <N>'

After any change: update the table above and append a line to the verification log. Class: firewall_change — record approval for production changes.

Not required for: local sudo k3s kubectl on the host, or API access only via SSH tunnel.

8472/udp: world-open rule removed (single-node). Re-add only if multi-node flannel peers need it.

UFW backup from remediation: /etc/ufw/user.rules.bak.20260716 on host.

Verification log

Date Result Notes
2026-07-16 OK ICMP OK; ssh railiance01 shell OK; host_observe assessment (RU-01)
2026-07-16 OK UFW 6443 restricted to allowlist; 8472 closed externally (P4)

Revocation

Date Action
open On ramp-down: stop renewing agent certs/keys used for this engagement; set schedule disabled; remove temporary admin UFW rules if desired; mark here