Finding
Weekly review (2026-09-21) of the migrate to chezmoi commit (7398c37, 2026-09-16) and current master.
Issue #135 flagged 2 personal hostnames (nixos-beelink-1, nixos-gmktec-1) in the top-level reference mirror ssh/config, with a fix proposed in #139 (not yet merged). That mirror is not what actually gets deployed anymore — since the chezmoi migration, home-chezmoi/private_dot_ssh/config is the live source (.chezmoiroot → home-chezmoi), and it has drifted further:
Host nixos-beelink-1 → HostName nixos-beelink-1
Host nixos-gmktec-1 → HostName nixos-gmktec-1
Host hp-laptop-1 → HostName hp-laptop-1
Host nas-1 → HostName stansyn1.tail861ef1.ts.net
Host oracle-1 → HostName oracle-1
Host google-1 → HostName google-1
Two things make this worse than #135:
- 4 additional personal hosts (
hp-laptop-1, nas-1, oracle-1, google-1) that were never in the mirror at all.
nas-1's HostName is a real, resolvable Tailscale MagicDNS name (stansyn1.tail861ef1.ts.net), which leaks the tailnet ID — more identifying than a bare unresolvable local hostname.
Note the private_ chezmoi prefix only sets file permissions (0600) on the deployed file; it does not exclude the file from the git history, and this repo (stanfish06/my-configs) is public.
Per repo convention (school HPC hostnames are fine to publish, personal/own-infra hosts are not — same standard applied in #135), these six hosts should not be tracked in the public repo.
Fix
PR incoming: removes the personal Host blocks from both ssh/config and home-chezmoi/private_dot_ssh/config, adds Include ~/.ssh/local/*.conf to each (same pattern already proposed in #139) so personal hosts can be defined locally, untracked. HPC entries (greatlakes*, bridges2) and the shared Host * block are untouched.
Suggested follow-up (not blocking this fix)
The actual leak was on nas-1's HostName, not the Host alias — for local-network devices you may want to keep using bare local hostnames as HostName (fine, not publicly resolvable) but avoid committing a Tailscale MagicDNS name specifically, since that's globally resolvable and identifies your tailnet.
Priority
Medium — no credentials exposed, but broader personal-infrastructure fingerprinting than #135, and includes one genuinely resolvable hostname.
Finding
Weekly review (2026-09-21) of the
migrate to chezmoicommit (7398c37, 2026-09-16) and currentmaster.Issue #135 flagged 2 personal hostnames (
nixos-beelink-1,nixos-gmktec-1) in the top-level reference mirrorssh/config, with a fix proposed in #139 (not yet merged). That mirror is not what actually gets deployed anymore — since the chezmoi migration,home-chezmoi/private_dot_ssh/configis the live source (.chezmoiroot→home-chezmoi), and it has drifted further:Two things make this worse than #135:
hp-laptop-1,nas-1,oracle-1,google-1) that were never in the mirror at all.nas-1'sHostNameis a real, resolvable Tailscale MagicDNS name (stansyn1.tail861ef1.ts.net), which leaks the tailnet ID — more identifying than a bare unresolvable local hostname.Note the
private_chezmoi prefix only sets file permissions (0600) on the deployed file; it does not exclude the file from the git history, and this repo (stanfish06/my-configs) is public.Per repo convention (school HPC hostnames are fine to publish, personal/own-infra hosts are not — same standard applied in #135), these six hosts should not be tracked in the public repo.
Fix
PR incoming: removes the personal
Hostblocks from bothssh/configandhome-chezmoi/private_dot_ssh/config, addsInclude ~/.ssh/local/*.confto each (same pattern already proposed in #139) so personal hosts can be defined locally, untracked. HPC entries (greatlakes*,bridges2) and the sharedHost *block are untouched.Suggested follow-up (not blocking this fix)
The actual leak was on
nas-1'sHostName, not theHostalias — for local-network devices you may want to keep using bare local hostnames asHostName(fine, not publicly resolvable) but avoid committing a Tailscale MagicDNS name specifically, since that's globally resolvable and identifies your tailnet.Priority
Medium — no credentials exposed, but broader personal-infrastructure fingerprinting than #135, and includes one genuinely resolvable hostname.