Machines and CI
A CI runner, deploy host, or scheduled job can use fd0 with its own identity instead of a person's unlocked vault or a copied secret. The machine identity is an ordinary fd0 identity that unlocks with a key file and is a member of only the scopes it needs.
Create the machine identity
Run these as a dedicated service user that owns the identity's directory. Separate directories under one user do not keep processes apart. Create the key outside fd0, for example as a systemd credential.
$ export FD0_HOME=/var/lib/ci/fd0 $ umask 077; head -c 32 /dev/urandom | base64 > /etc/ci/fd0.key $ fd0 init --key-file /etc/ci/fd0.key $ fd0 unlock --key-file /etc/ci/fd0.key
The key file must be a regular file owned by that user or root, not readable by group or others, and hold at least 32 bytes. Use - to read it from stdin. With a key file, fd0 never falls back to a prompt.
Pin the server
# on your device: the server and safety number it pinned $ fd0 status --servers # on the machine $ fd0 sync --pin "12345 67890 ..."
Take the safety number from fd0 status --servers on a device that already uses the same server. --pin pins the server only if the numbers match, and refuses a server whose number differs later. Background sync never pins a server by itself.
Give it access
# on the machine $ fd0 card export # on your device $ fd0 card import "fd0://card/..." --label ci-runner $ fd0 scope add-member ci-runner --scope deploy --role reader $ fd0 sync # on the machine $ fd0 sync
Add the machine as reader, or writer if it rotates the values it uses. Neither can change who has access; see roles. Prefer a scope that holds only this machine's credentials, because every member can read everything in the scope.
Use it in a job
$ fd0 unlock --key-file "$CREDENTIALS_DIRECTORY/fd0.key" $ fd0 sync $ fd0 run --service app --scope deploy -- ./deploy.sh
fd0 unlock --key-file returns at once when the vault is already unlocked and unlocks again after a timeout, so run it at the start of every job.
Revoke a machine
Remove it from its scopes with fd0 scope remove-member ci-runner --scope deploy, then rotate every value it could read. One identity per machine and purpose; never copy its fd0 directory to another host.