Files
PFVCluster/proxmox/perf
mrcharles 1d7c74676c fix(access): ban guest-agent as access channel — SSH only [#403]
Previous sessions used `qm guest exec` to back-door SSH keys into ~30 VMs,
bypassing sshd's audit trail in an ITAR/CMMC environment. Wire the ban deep
so it cannot recur:

- tests/remote.sh: remove the vm-guest mode + qm-guest-exec path entirely
- scripts/check-rules.sh: rule #11 fails on any `qm guest exec` / `vm-guest`
  pattern in code (scans .sh/.bash/.py; docs may describe the ban freely)
- AGENTS.md: codify "Access-channel policy: SSH only" as non-negotiable;
  add "Questions" rule banning harness question tools (use questions-v1.md)
- tests/vm-validation.sh: drop guest-agent key re-injection; SSH-only
- proxmox/perf/scripts/perf-matrix.sh + deploy-tuned-guests.sh: convert
  guest-agent execution to SSH (vmroot) now that VMs have key + sudo
- bootstrap-all.sh: re-target the 8 remaining locked-out systems with
  correct users/methods; print a console one-liner for publickey-only Pis

Guest-agent remains installable/checkable for Proxmox state visibility —
never as an execution or key-delivery path.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-10 16:03:16 -05:00
..
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00
2026-08-01 15:45:23 -05:00