# compliance repo consumes no secrets from env files by design: node access is # root-SSH over Tailscale (keys via ssh-agent), and env.sh (sourced) holds # node rosters + wire-plan constants. Copy env.sh values from the cluster # runbook; never commit real kubeconfigs or tokens. # # Optional overrides when driving scripts by hand: #SSH_USER=reachableceo #SSH_OPTS=(-o BatchMode=yes -o StrictHostKeyChecking=accept-new -o ConnectTimeout=15)