Capability Gates
A capability gate decides whether one action reaches a host. It decides on the consequence of the action, and never on the text of a command.
A capability gate decides whether one action reaches a host. It decides on the consequence of the action, and never on the text of a command.
By default nanoinfra authenticates a token, not a person. Two operators who share that token are
This guide covers the practical controls to review before letting a nanoinfra
nanoinfra is not an OIDC client. It runs no login flow, holds no client secret and knows
One nanoinfra process serves one tenant. To serve several, run several processes — one config
Store credentials safely, and keep an inventory of the machines you manage. The agent connects to one host and runs something there. The credential never passes through the agent itself.
Every field that decides what needs approval, who may give it, and who is allowed to talk to