Skip to content

feat(tailscale): permit agentcompute HTTPS and Studio SSH - #22

Merged
jmgilman merged 1 commit into
masterfrom
feat/agentcompute-service-policy
Sep 15, 2026
Merged

jmgilman merged 1 commit into
masterfrom
feat/agentcompute-service-policy

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Supersedes #21 with the explicitly requested minimal policy. Add tag:agentcompute owned only by autogroup:admin; alias studio-1 to 100.122.142.76 without retagging it; allow service-to-Studio TCP 22 and member-to-service TCP 443. Preserve the existing admin blanket and all unrelated policy. No port ranges starting at zero are introduced.

Policy tests cover Studio SSH, denied VNC and representative other SSH destinations, sandbox-to-Studio denial, and member HTTPS. CI must validate before merge; awaiting owner approval. Native sshd/authorized_keys source pinning remains a separate deployment acceptance requirement, not replaced by ACL tests.

@jmgilman
jmgilman merged commit 1e43e83 into master Sep 15, 2026
2 checks passed
@jmgilman
jmgilman deleted the feat/agentcompute-service-policy branch September 15, 2026 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant