CHANNEL • SECURITY • AUDITABILITY

Case Study: The Restricted SSH Instruction Channel (Forced-Command, Stdin Pipe, Full Audit Trail)

2026-05-29
12 min read

The entire bidirectional instruction fabric between the persistent Hetzner Organizer and the local OperatorSuperGROK laptop runs over a single SSH key with a forced-command wrapper. No broad rsync, no interactive shells, no arbitrary commands. Every action is explicitly allow-listed and logged.

Core Primitives

The handler (server-instruction-handler.sh) is the only thing the key can ever execute. This is the model that survived the first real high-fidelity obs test and enabled the creative velocity the user demanded.

agents/ssh-agent/scripts/server-instruction-handler.sh • DR-20260531-073 • organizer/context.py:get_ssh_channel_context_block + publish_ssh_instruction