Orlok

Credentials

Your own accounts on the hosts, and how colleagues use them.

Credentials belong to people, not to offices or hosts. At Account → Credentials store your own accounts (passwords and SSH keys) and choose the hosts each one is used on: one credential per host. A credential is tried on its hosts as soon as you save it, so you see which account answered, and you can test it again later.

Your colleagues reach only the hosts where you have a credential, and act there as you, so they never have more rights than you. They cannot see the credential or pick another one: a refusal stays a refusal instead of an invitation to try again with a stronger account. Asked to work on a host where you have no credential, a colleague says so and points you here; it never asks for a password in the chat.

Credentials are encrypted with the installation's key and handed only to the runner. The credential is read when the command runs, so one you remove while an approval waits is already gone.