Per-host SSH access blocks (BLK milestone)
Monorepo version bump 3.4.2 → 3.5.0 (root/frontend/backend). This release delivers the
per-host SSH access-blocks milestone (BLK-00..BLK-13): the ability to block a specific
user/identity on a specific host by composing a per-host KRL, signed by the Host CA and
distributed via the existing encrypted per-host endpoint — without revoking the user's
certificate everywhere.
Highlights
Composed per-host KRLs
SshHostKrlService(TASK-180) — builds a composed per-host KRL with a global
monotonic number and Host-CA signing, so each host receives exactly the revocations
that apply to it, anti-rollback intact.- Serving cutover (TASK-183) — the public per-host endpoints now serve the ECIES payload
straight fromssh_host_krls, replacing the previous composition path. - Freshness triggers (TASK-182) — certificate issuance and revocation automatically
regenerate the affected per-host KRLs so distribution stays current. - Trust-anchor reconciliation (TASK-187) — the puller's trust anchor is reconciled to
the Host-CA public key end-to-end, matching what signs the composed KRL.
Blocking model & API
SshBlockService(TASK-181) — block/unblock an identity on a host, with synchronous
per-host KRL regeneration and full lifecycle handling.ssh.block.*API (TASK-185) — block operations plus a host-access/state read model,
exposed as tRPC + REST twins.- Per-host KRL state + metrics (TASK-184) — state derivation and lineage metrics for
observability of each host's KRL. - Optional zero-window issuance gate (TASK-190) — a flag-gated issuance gate that closes
the window between issuing and blocking.
Frontend
- Host Access card, Users "blocked-on" pills, and KRL distribution columns (TASK-186) —
surface per-host block state and distribution status directly in the UI.
Testing, docs & hardening
- E2E block matrix (TASK-188) — composed-KRL blocking verified against real sshd and
the real krl-client, including anti-rollback. - Ansible + operator docs (TASK-189) — per-host KRL option, operator guide, and a cutover
runbook. - Adversarial-review fixes — closed the findings from a full-milestone-diff review
(incl. a steady-state renewal regression in the BLK-13 gate).
Release artifacts (krl-client)
| Asset | Purpose |
|---|---|
krl-client-linux-amd64
| static, CGO_ENABLED=0, -trimpath linux/amd64 binary
|
checksums.txt
| SHA-256 checksum of the binary |
krl-client-linux-amd64.sig
| keyless cosign signature |
krl-client-linux-amd64.pem
| cosign certificate (Fulcio) |
krl-client-linux-amd64.spdx.json
| SPDX SBOM (syft) |
Full Changelog: v3.4.2...v3.5.0