Skip to content

authkeys that can bypass manual machine auth #2120

@apenwarr

Description

@apenwarr

Manual machine authorization works well for human-owned client devices, but is very inconvenient when used with automated management of servers and especially containers. Admins then have to compromise by enabling or disabling the manual auth flag globally, affecting both client devices and servers.

The servers & containers in question are almost always configured with preauth keys. We could allow the user to give certain preauth keys a special "bypass manual device auth" flag. Then those preauthed devices wouldn't need to be manually approved.

See also #1124, which discussed letting unauthorized devices have different ACLs entirely. That could be an alternative to this, but is semantically a bit confusing.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions