Skip to content

fix: inspect remaining gateways through protected identity - #162

Merged
Pigbibi merged 1 commit into
mainfrom
codex/gateway-remaining-passive-20261001
Oct 1, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
codex/gateway-remaining-passive-20261001

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Scope

Extend the existing protected remaining-target diagnostic to passive connection inspection. Keep the default metadata mode and completed target unchanged.

Changes

  • Derive the three remaining indices from protected inventory and validate their existing SSH configuration.
  • Require exact VM resource identity before reading the existing SSH key or opening one bounded IAP session.
  • Preserve per-target authentication, masking, cleanup and single-attempt behavior.
  • Reject remaining-target SSH policy and key-binding combinations. No broker calls or permission changes.

Validation

Author: resolver, passive shell, metadata shell, shared workflow config, seven SSH diagnostic tests, actionlint, shell syntax and diff checks passed.
Root: resolver, metadata shell, passive shell, seven SSH diagnostics, actionlint and diff checks passed. Independent material review passed for this scope.

Actual per-target Secret/IAP access and passive socket observations remain to be verified. These observations do not prove broker authentication or business recovery.

…tity

Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi
Pigbibi merged commit c364614 into main Oct 1, 2026
2 checks passed
@Pigbibi
Pigbibi deleted the codex/gateway-remaining-passive-20261001 branch October 1, 2026 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant