diff --git a/config/athena-operator-known-hosts b/config/athena-operator-known-hosts new file mode 100644 index 0000000..20066c4 --- /dev/null +++ b/config/athena-operator-known-hosts @@ -0,0 +1 @@ +[192.168.1.2]:33 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBMz8WHIg09GxMuqmeGoGs4lV2lT+vntgarPwoecQHhJ diff --git a/config/athena-operator.env.example b/config/athena-operator.env.example index 0231249..ecd568d 100644 --- a/config/athena-operator.env.example +++ b/config/athena-operator.env.example @@ -4,7 +4,8 @@ ATHENA_OPERATOR_STATE=/data/mike-ai-operator/state ATHENA_OPERATOR_MODELS=/data/models ATHENA_OPERATOR_SOCKET=/run/mike-ai-operator/operator.sock ATHENA_OPERATOR_GID=10003 -ATHENA_OPERATOR_GIT_REMOTE=git@192.168.1.2:michael/AI-Profile-Router.git +ATHENA_OPERATOR_GIT_REMOTE=ssh://git@192.168.1.2:33/michael/AI-Profile-Router.git ATHENA_OPERATOR_GIT_SSH_KEY=/etc/mike-ai/athena-operator-git +ATHENA_OPERATOR_GIT_KNOWN_HOSTS=/etc/mike-ai/athena-operator-known-hosts ATHENA_OPERATOR_GIT_NAME=Athena Operator ATHENA_OPERATOR_GIT_EMAIL=athena-operator@localhost diff --git a/platform/mcp/README.md b/platform/mcp/README.md index 12dbde8..29f9ce9 100644 --- a/platform/mcp/README.md +++ b/platform/mcp/README.md @@ -49,6 +49,10 @@ Für Git-Publishing besitzt Athena ein eigenes Schlüsselpaar unter in Gitea als schreibberechtigter Deploy-Key für `AI-Profile-Router` hinterlegt. Der private Schlüssel verlässt Athena nicht und wird weder an den MCP-Container noch an das Modell ausgegeben. +Der Gitea-Endpunkt ist als `ssh://...:33/...` konfiguriert; sein auf dem +Administrator-Mac verifizierter Ed25519-Hostschlüssel ist in +`config/athena-operator-known-hosts` fest gebunden. Ein unerwarteter +Hostschlüsselwechsel stoppt Git-Zugriffe, statt ihn still zu akzeptieren. TinySearch bleibt als Ganzes read-only. Nur das flüchtige tmpfs-Verzeichnis `/home/tinysearch/.crawl4ai` ist beschreibbar, weil Crawl4AI dort seinen diff --git a/platform/operator/athena_operatord.py b/platform/operator/athena_operatord.py index 4232f15..ad5c83a 100755 --- a/platform/operator/athena_operatord.py +++ b/platform/operator/athena_operatord.py @@ -77,9 +77,11 @@ def run(argv: list[str], *, cwd: Path = STACK, timeout: int = 900, check: bool = "HOME": "/root", } git_key = Path(os.environ.get("ATHENA_OPERATOR_GIT_SSH_KEY", "/etc/mike-ai/athena-operator-git")) + known_hosts = Path(os.environ.get("ATHENA_OPERATOR_GIT_KNOWN_HOSTS", "/etc/mike-ai/athena-operator-known-hosts")) if git_key.is_file(): environment["GIT_SSH_COMMAND"] = ( f"ssh -i {shlex.quote(str(git_key))} -o IdentitiesOnly=yes " + f"-o UserKnownHostsFile={shlex.quote(str(known_hosts))} " "-o StrictHostKeyChecking=yes" ) completed = subprocess.run( diff --git a/platform/operator/install-operator.sh b/platform/operator/install-operator.sh index 34b844c..30ba127 100755 --- a/platform/operator/install-operator.sh +++ b/platform/operator/install-operator.sh @@ -12,6 +12,8 @@ if [[ ! -e /etc/mike-ai/athena-operator-git ]]; then fi chmod 0600 /etc/mike-ai/athena-operator-git chmod 0644 /etc/mike-ai/athena-operator-git.pub +install -m 0644 "$ROOT/config/athena-operator-known-hosts" \ + /etc/mike-ai/athena-operator-known-hosts install -d -m 0750 -o root -g 10003 /run/mike-ai-operator install -d -m 0700 /data/mike-ai-operator/state /data/mike-ai-operator/repository install -m 0755 "$ROOT/platform/operator/athena_operatord.py" /usr/local/libexec/mike-ai-athena-operatord