docs(ssh): SSH-first setup path as a peer of the token path; COMPARISON/COMPAT rows for mode differences #299

Closed
opened 2026-07-20 15:15:37 +00:00 by hexajon · 0 comments
hexajon commented 2026-07-20 15:15:37 +00:00 (Migrated from codeberg.org)

Part of #187 (SSH-only mode epic). Depends on the build slices landing.

The setup docs gain an SSH-first path of equal standing with the token path: choosing a protocol mode at login, the preflight, what works token-less and what degrades (with the typed error's own wording quoted), and the honest security notes from the epic (no credential on the git wire; known_hosts TOFU and the fingerprint steer; madtea guards token storage but cannot guard a passphrase-less key file). COMPARISON.md/COMPAT.md get their terse rows wherever a flag/action/platform caveat differs by mode.

Acceptance:

  • docs/guides/setup.md (or a peer guide, whichever reads better) presents SSH-first as a first-class path, not a footnote
  • The degradation behavior of ssh-only mode is documented with the actual error text
  • The security rationale and its counterweights are stated plainly
  • COMPARISON/COMPAT rows updated for every flag/action this epic added (terse mentions, per the docs convention)
  • Cross-links: install/setup/clients guides reference the mode where relevant
Part of #187 (SSH-only mode epic). Depends on the build slices landing. The setup docs gain an SSH-first path of equal standing with the token path: choosing a protocol mode at login, the preflight, what works token-less and what degrades (with the typed error's own wording quoted), and the honest security notes from the epic (no credential on the git wire; known_hosts TOFU and the fingerprint steer; madtea guards token storage but cannot guard a passphrase-less key file). COMPARISON.md/COMPAT.md get their terse rows wherever a flag/action/platform caveat differs by mode. Acceptance: - [ ] docs/guides/setup.md (or a peer guide, whichever reads better) presents SSH-first as a first-class path, not a footnote - [ ] The degradation behavior of ssh-only mode is documented with the actual error text - [ ] The security rationale and its counterweights are stated plainly - [ ] COMPARISON/COMPAT rows updated for every flag/action this epic added (terse mentions, per the docs convention) - [ ] Cross-links: install/setup/clients guides reference the mode where relevant
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
sixfold-space/madtea#299
No description provided.