carlok — zsh — 88×30

cat _posts/2026-09-25-portcullis-phase-1-stops-accepting-any-ssh-host-key.md

portcullis: Phase 1 stops accepting any SSH host key

portcullis replaced paramiko’s AutoAddPolicy — which accepts whatever key a host presents — with an explicit trust-on-first-use policy (25da71b). Phase 1 is the first contact with a VM created seconds earlier by the same process, so there is no prior key to compare against and Hetzner does not publish the fingerprint through its API: the new policy accepts that first key once, logs its type and fingerprint, and Phase 2 still connects with that exact key pinned, so a later substitution is detected. The change addresses CodeQL’s py/paramiko-missing-host-key-validation alert, and the test that asserted the blanket policy now asserts the new one. The secret-handling pass of 21 September had already pinned the key Phase 2 connects with; the first contact was still an unconditional accept.