Skip to content

feat(team-vault): accept connection knock sequences as a team secret - #100

Merged
kipavy merged 1 commit into
mainfrom
feat/550-knock-sequence-secret
Oct 7, 2026
Merged

kipavy merged 1 commit into
mainfrom
feat/550-knock-sequence-secret

Conversation

@kipavy

@kipavy kipavy commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Part of VoltiusApp/voltius#550 (port knocking before SSH connect).

Team vaults now accept a host's knock port sequence as a team secret, in the same way as the per-host proxy password (#57).

  • Migration 055_connection_knock_sequence_secret_type.sql widens team_vault_secrets_secret_type_check with connection_knock_sequence. It has the same shape as 043, and every existing type is kept.
  • secret_owner_type maps it to connection, so writing it needs PERM_EDIT_CONNECTIONS. canonical_secret_id gives knock_sequence:<object_id>.
  • Reads need no change: list_secrets already returns every type to members holding PERM_CONNECT or PERM_VIEW_SECRETS (#190), so connect-only members receive the sequence they need to knock.

Deploy order: deploy this before the client release that ships port knocking. Until it is deployed, saving a knock sequence on a team-vault host fails.

Tests: the canonical-id table, the edit_permission_for_secret_type mapping, and a DB-backed upsert_secret_accepts_connection_knock_sequence. cargo test team_objects passes 80/80 against the test database.

@kipavy
kipavy merged commit ef631c0 into main Oct 7, 2026
1 check passed
@kipavy
kipavy deleted the feat/550-knock-sequence-secret branch October 7, 2026 22:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant