Access Onboarding
Follow the FROM House device-onboarding contract rather than copying private keys between machines.
Expected local key alias:
~/.ssh/relik-pi4
Key rule:
- Generate or reuse a device-local private key at that path.
- Send only the matching public key to MJF through an approved channel.
- MJF installs the public key on the needed hosts and Forgejo account if Git access is required.
- Do not put private keys, Tailscale auth keys, OAuth tokens, browser cookies, raw session tokens, or full authorized key bundles in this workspace.
Canonical Name Guard
The lab name is always RELiK.
Any durable workspace documentation that says Relic,
Relik, RELIK, relic, or
relik when referring to the lab should be corrected to
RELiK.