Skip to content

Chezmoi-deployed ssh config leaks 6 personal server hostnames (worse than #135) #147

Description

@stanfish06

Finding

Weekly review (2026-09-21) of the migrate to chezmoi commit (7398c37, 2026-09-16) and current master.

Issue #135 flagged 2 personal hostnames (nixos-beelink-1, nixos-gmktec-1) in the top-level reference mirror ssh/config, with a fix proposed in #139 (not yet merged). That mirror is not what actually gets deployed anymore — since the chezmoi migration, home-chezmoi/private_dot_ssh/config is the live source (.chezmoiroot → home-chezmoi), and it has drifted further:

Host nixos-beelink-1  → HostName nixos-beelink-1
Host nixos-gmktec-1   → HostName nixos-gmktec-1
Host hp-laptop-1      → HostName hp-laptop-1
Host nas-1            → HostName stansyn1.tail861ef1.ts.net
Host oracle-1         → HostName oracle-1
Host google-1         → HostName google-1

Two things make this worse than #135:

  • 4 additional personal hosts (hp-laptop-1, nas-1, oracle-1, google-1) that were never in the mirror at all.
  • nas-1's HostName is a real, resolvable Tailscale MagicDNS name (stansyn1.tail861ef1.ts.net), which leaks the tailnet ID — more identifying than a bare unresolvable local hostname.

Note the private_ chezmoi prefix only sets file permissions (0600) on the deployed file; it does not exclude the file from the git history, and this repo (stanfish06/my-configs) is public.

Per repo convention (school HPC hostnames are fine to publish, personal/own-infra hosts are not — same standard applied in #135), these six hosts should not be tracked in the public repo.

Fix

PR incoming: removes the personal Host blocks from both ssh/config and home-chezmoi/private_dot_ssh/config, adds Include ~/.ssh/local/*.conf to each (same pattern already proposed in #139) so personal hosts can be defined locally, untracked. HPC entries (greatlakes*, bridges2) and the shared Host * block are untouched.

Suggested follow-up (not blocking this fix)

The actual leak was on nas-1's HostName, not the Host alias — for local-network devices you may want to keep using bare local hostnames as HostName (fine, not publicly resolvable) but avoid committing a Tailscale MagicDNS name specifically, since that's globally resolvable and identifies your tailnet.

Priority

Medium — no credentials exposed, but broader personal-infrastructure fingerprinting than #135, and includes one genuinely resolvable hostname.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions