mirror of
https://github.com/trailofbits/algo.git
synced 2026-09-02 14:28:53 +02:00
The sshd_config file was being written with incorrect indentation due to the indent filter having first=True, which added 6 spaces to the first line of the template. This caused SSH daemon to fail parsing the config file, preventing SSH connections on the configured port (4160). Changed indent(width=6, first=True) to indent(width=6, first=False) to ensure the SSH configuration is written without leading spaces on each line, allowing sshd to properly parse the configuration. Fixes SSH connection timeouts during DigitalOcean deployments. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
Cloud-Init Files - Critical Format Requirements
⚠️ CRITICAL WARNING ⚠️
The files in this directory have STRICT FORMAT REQUIREMENTS that must not be changed by linters or automated formatting tools.
Cloud-Config Header Format
The first line of base.yml MUST be exactly:
#cloud-config
❌ DO NOT CHANGE TO:
# cloud-config(space after #) - BREAKS CLOUD-INIT PARSING- Add YAML document start
---- NOT ALLOWED IN CLOUD-INIT
Why This Matters
Cloud-init's YAML parser expects the exact string #cloud-config as the first line. Any deviation causes:
- Complete parsing failure - All directives are skipped
- SSH configuration not applied - Servers remain on port 22 instead of 4160
- Deployment timeouts - Ansible cannot connect to configure the VPN
- DigitalOcean specific impact - Other providers may be more tolerant
Historical Context
- Working: All versions before PR #14775 (August 2025)
- Broken: PR #14775 "Apply ansible-lint improvements" added space by mistake
- Fixed: PR #14801 restored correct format + added protections
See GitHub issue #14800 for full technical details.
Linter Configuration
These files are excluded from:
yamllint(.yamllintconfig)ansible-lint(.ansible-lintconfig)
This prevents automated tools from "fixing" the format and breaking deployments.
Template Variables
The cloud-init files use Jinja2 templating:
{{ ssh_port }}- Configured SSH port (typically 4160){{ lookup('file', '{{ SSH_keys.public }}') }}- SSH public key
Editing Guidelines
- Never run automated formatters on these files
- Test immediately after any changes with real deployments
- Check yamllint warnings are expected (missing space in comment, missing ---)
- Verify first line remains exactly
#cloud-config