ldap goes state-only, HM leaves the system config, and four hosts drop the local account #120
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ldap-state-only-hm-split"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
openldap.nix: theopenldap-seedunit is gone entirely - directory content (DIT structure, people, groups,svc-ldap/svcLdapAdmin) is now hand-managed runtime state (ldap-tui/kadmin), borg-backed like anything else persistentldapBindPasswordsecret app hosts need to bind - it no longer creates or reconciles contentldapaddthat could never self-heal a baduidNumber/gidNumberonce seeded - the actual root cause of the prior sudo lockout (cn=wheelwasgidNumber: 1001,cn=systemd-journalwas1002, vs. NixOS's real1/62- fixed live vialdapmodifythis session)openldap/saslauthd/sssdhealthy, seed unit stopped/removed, all prior directory content survived intact.claude/CLAUDE.md: drops the stale "keep unused function args" rule - superseded by adoptingdeadnix, which now flags them as part of thenix flake checkgatemodules/homeConfigurations/server.nixadds a sharedlament@serverhomeConfiguration (mirrors ishtar'slament@desktopsplit - same modules as the integrated server profile, decoupled fromnixos-rebuild)brigidpilots it (modules.lament.standalone = true) - lowest-stakes real server, not the identity box or the shared app tierjust hometakes aprofilearg now (defaultdesktop) so servers can runjust home serverlamentUseraccount is untouched on brigid - this only proves standalone HM converges on real hardware before local-account removal gets attempted againfac06d34af1c7c7f09921c7c7f099263d996493763d99649374c407217f0ab3d0418a13cecf6b719ldap goes state-only, and brigid pilots standalone HMto ldap goes state-only, HM leaves the system config, and four hosts drop the local account