SCRUM-243 — Deploy: SSH tunnel script and admin access guide¶
Plan ref: OPS-4 (docs/11-admin-plane-plan.md). Stacked on SCRUM-230.
What exists¶
| Piece | Notes |
|---|---|
deploy/scripts/tunnel.sh |
ssh -N -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -L ${LOCAL_PORT:-8090}:127.0.0.1:8090 ${OTOMO_SSH:-team45@team45.dp-ext8.com}; refuses when the local port is taken (nc / ss / netstat / bash fallback); --help |
deploy/docs/ADMIN-ACCESS.md |
zero-to-signed-in guide: prerequisites (Chrome/Firefox; Safari unsupported for Secure cookies on http://localhost), tunnel, first root sign-in (sudo cat …/root_password), inviting, accepting, everyday sign-in, MFA, reset, troubleshooting, root rotation, and an "until the UI exists" API walkthrough |
deploy/README.md |
pointer section |
The guide opens with an honest current build status: the Users page (SCRUM-257) and onboarding screen (SCRUM-258) do not exist yet, so invites are API-level for now; MFA arrives with SCRUM-208.
Product gap found: no endpoint lets an admin reset another user's MFA. Someone who loses both the authenticator and the recovery codes is locked out. This needs a follow-up ticket.
How to verify¶
sh -n deploy/scripts/tunnel.sh && sh deploy/scripts/tunnel.sh --help
deploy/scripts/tunnel.sh # with SSH access; then open http://localhost:8090/admin/
Results at time of writing¶
sh -n,--help: pass. Port-in-use refusal checked by reading; the live tunnel was not opened from this session.- Guide checked against the code of admin-auth (#50 for MFA), adminui routes, and deploy scripts.
How it was built¶
DeepSeek run scoped (Landlock) to deploy (reasoning effort low). Claude review:
corrected the MFA status (DeepSeek read a branch without SCRUM-208), added the
non-default-port caveat for invite links, and recorded the MFA-reset gap.