Files
dendritic/modules/hosts/janus/README.md
T
2026-07-03 23:29:20 -05:00

2.3 KiB

Janus

Generate passwords:

mkdir -p /tmp/janus-step-ca-bootstrap && chmod 700 /tmp/janus-step-ca-bootstrap && cd /tmp/janus-step-ca-bootstrap && umask 077 && openssl rand -base64 48 > ca_password.txt && openssl rand -base64 48 > admin_jwk_password.txt

Bootstrap CA materials with SSH enabled:

STEPPATH=/tmp/janus-step-ca-bootstrap/step step ca init --name Janus --dns janus.john-stream.com --dns 192.168.1.244 --address :443 --provisioner admin --password-file /tmp/janus-step-ca-bootstrap/ca_password.txt --provisioner-password-file /tmp/janus-step-ca-bootstrap/admin_jwk_password.txt --ssh --deployment-type standalone --with-ca-url https://janus.john-stream.com

Insert generated runtime CA material into modules/hosts/janus/secrets.yaml under janus:

  • /tmp/janus-step-ca-bootstrap/ca_password.txt -> ca_password
  • /tmp/janus-step-ca-bootstrap/step/certs/intermediate_ca.crt -> intermediate_ca_crt
  • /tmp/janus-step-ca-bootstrap/step/secrets/intermediate_ca_key -> intermediate_ca_key
  • /tmp/janus-step-ca-bootstrap/step/secrets/ssh_host_ca_key -> ssh_host_ca_key
  • /tmp/janus-step-ca-bootstrap/step/secrets/ssh_user_ca_key -> ssh_user_ca_key
  • /tmp/janus-step-ca-bootstrap/step/config/ca.json -> admin_provisioner_encrypted_key (copy authority.provisioners[].encryptedKey for the admin JWK provisioner)

If you are only validating wiring first, admin_provisioner_encrypted_key can be an encrypted placeholder and replaced later.

If rotating provisioner password, also set:

  • /tmp/janus-step-ca-bootstrap/admin_jwk_password.txt -> janus.admin_jwk in keys/secrets.yaml

Secret source-of-truth after this split:

  • modules/hosts/janus/secrets.yaml: Janus runtime CA secrets (ca_password, intermediate_ca_crt, intermediate_ca_key, ssh_host_ca_key, ssh_user_ca_key, admin_provisioner_encrypted_key)
  • keys/secrets.yaml: shared Janus provisioner secret (janus.admin_jwk) consumed by step-ssh-host across hosts

Then update public artifacts in repo from generated output:

  • modules/hosts/janus/root_ca.crt from /tmp/janus-step-ca-bootstrap/step/certs/root_ca.crt
  • modules/hosts/janus/fingerprint from:
    step certificate fingerprint /tmp/janus-step-ca-bootstrap/step/certs/root_ca.crt
    
  • modules/hosts/janus/ssh_user_ca.pub from /tmp/janus-step-ca-bootstrap/step/certs/ssh_user_ca_key.pub