Identities and access boundaries
Shipyard uses its own Google worker identity, GitHub authentication/signing key, Claude/Codex subscription sign-ins, and persistent browser login. They are separate credentials with separate recovery paths. Configuration portability is not credential copying.
The worker identity is akshat-shipyard@test-ai-243511.iam.gserviceaccount.com. Its key is ~/.config/dev-environment/google-worker.json with mode 0600. CLI and ADC use the same curated identity; Spot finds a symlink under gcloud’s sa-keys directory. google-auth.sh activates the worker account and links ADC; it changes local auth configuration and should not be run just to inspect it.
Direct production/shared grants are restricted; staging grants support selected application writes. Build monitoring allows inspection/logs, not submit/cancel or trigger administration. Kubernetes debugging includes routine exec and port-forwarding in selected app namespaces, but not direct Secret reads, pod deletion or deployment edits.
Pod execution can use application credentials and network access. Direct worker restrictions do not guarantee no production deletion through those sessions. No production mutation is part of diagnostics or documentation validation.
Existing Terraform owns IAM and generated Kubernetes RBAC. This personal repository documents consumers and recovery; it does not introduce a new grant provisioner. Seventeen Bigtable grants and some runtime secrets remained unresolved in the setup record. Verify the denied operation before proposing a scope change.
The three custom exceptions cover BigQuery staging data, Firestore read-only and project query operations (the latter also gained Cloud SQL discovery). Prefer scoped standard roles for new requirements; use the existing owner to review/apply changes. Permission changes ordinarily reuse the same identity and key.
Home test bed machines
Section titled “Home test bed machines”The edge appliance accepts only SSH certificates signed by Spot’s Vault. The Mac’s shell wraps ssh for hosts matching *.spotai.co or sn<digit>*: it logs into Vault by OIDC when the token is stale, writes the signed certificate to ~/.ssh/signed-cert.pub (valid 24 hours) and passes it with the key. The build server trusts the Mac’s plain key as pi. When the build server must reach the appliance (a library copy, a binary copy), the Mac forwards its agent with ssh -A; nothing is added to the appliance. Both machines give pi passwordless sudo. See access on the appliance page.
GitHub and agent sign-ins
Section titled “GitHub and agent sign-ins”GitHub login, commit author identity, and signing identity are distinct. Shipyard has a dedicated signing key while retaining the normal author name/email. GitHub’s displayed username is not a reliable machine indicator; no visual marker was requested.
Claude and Codex were authenticated interactively on Shipyard using subscriptions. Keep those credentials on Shipyard. This repository does not invoke paid agent prompts to test authentication or synchronize credential stores. Read-only local status is enough for diagnosis; expired sessions need their native login flows.
Private package registry and browser
Section titled “Private package registry and browser”Artifact Registry npm tokens are short-lived. Refresh them with the scoped registry helper only after checking the worker identity. Do not commit .npmrc token values. Browser login lives in the private Linux profile and may require human consent or renewed login.
Mac and Shipyard do not yet have all the same skills and MCP access. A Playwright connection does not prove every integration is available. Access recovery.