Credential Repair Rule
Credential fixes must follow the FROM House key model.
- Use per-device or per-session private keys at the stable local contract path.
- Send or register public keys only; never copy private keys between devices.
- Do not silently replace keys to make a single device work.
- If Pi, VPS, Forgejo, or repo access changes, record the change in the Forgejo source-of-truth path that owns the feed or operating procedure.
- If feed metadata, authorized keys, and Forgejo key titles disagree, treat that as credential drift until reconciled.
Working Rule
If any instruction conflicts about the lab name, defer to this exact
spelling: RELiK.