Skip to content

SCRUM-243 — Deploy: SSH tunnel script and admin access guide

Plan ref: OPS-4 (docs/11-admin-plane-plan.md). Stacked on SCRUM-230.

What exists

Piece Notes
deploy/scripts/tunnel.sh ssh -N -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -L ${LOCAL_PORT:-8090}:127.0.0.1:8090 ${OTOMO_SSH:-team45@team45.dp-ext8.com}; refuses when the local port is taken (nc / ss / netstat / bash fallback); --help
deploy/docs/ADMIN-ACCESS.md zero-to-signed-in guide: prerequisites (Chrome/Firefox; Safari unsupported for Secure cookies on http://localhost), tunnel, first root sign-in (sudo cat …/root_password), inviting, accepting, everyday sign-in, MFA, reset, troubleshooting, root rotation, and an "until the UI exists" API walkthrough
deploy/README.md pointer section

The guide opens with an honest current build status: the Users page (SCRUM-257) and onboarding screen (SCRUM-258) do not exist yet, so invites are API-level for now; MFA arrives with SCRUM-208.

Product gap found: no endpoint lets an admin reset another user's MFA. Someone who loses both the authenticator and the recovery codes is locked out. This needs a follow-up ticket.

How to verify

sh -n deploy/scripts/tunnel.sh && sh deploy/scripts/tunnel.sh --help
deploy/scripts/tunnel.sh      # with SSH access; then open http://localhost:8090/admin/

Results at time of writing

  • sh -n, --help: pass. Port-in-use refusal checked by reading; the live tunnel was not opened from this session.
  • Guide checked against the code of admin-auth (#50 for MFA), adminui routes, and deploy scripts.

How it was built

DeepSeek run scoped (Landlock) to deploy (reasoning effort low). Claude review: corrected the MFA status (DeepSeek read a branch without SCRUM-208), added the non-default-port caveat for invite links, and recorded the MFA-reset gap.