SSH certificates¶
OpenBao is a certificate authority for SSH user keys. A member of the Application Hosting Team logs in to OpenBao through authentik, has their own public key signed, and gets a certificate that a host accepts for five hours. Nobody's key has to be added to a host, and nothing has to be removed when someone leaves: their next certificate is simply refused.
| Piece | Where |
|---|---|
ssh secrets engine mount |
terraform/40_openbao-config |
CA, signing role admin, policy ssh-sign-admin |
terraform/50_ssh-certificates |
ssh-sign-admin on the OIDC role authentik |
terraform/50_authentik-config — see OpenBao |
| hosts trusting the CA | nix/modules/ssh-user-ca.nix, gewis.sshUserCa.enable |
Only s3-01 enables it so far. The service PCs run NetBird's own SSH server, see NetBird for why that needs thought first. Talos nodes have no SSH at all.
The certificate names the account — root or cbc — and its key ID names the
person, oidc-<username>, which sshd logs on every login. That is enough while
one team has the same access everywhere; giving different groups different hosts
would mean switching to principals that each host maps to its accounts through
AuthorizedPrincipalsFile.
The other ways in stay: the break-glass key in root's authorized_keys on
s3-01 (see s3-01) and the cbc password on the service PCs.