Skip to content
C.W.K.
Stream
Lesson 04 of 04 · published

Keys, Jumps, and Files — Staged, Not Souvenirs

~12 min · m4, m5, m6, keys, sftp, destination

Level 0Spark
0 XP0/36 lessons0/12 achievements
0/100 XP to next level100 XP to go0% complete

The Rest of the Authorized Product

Once the phone owns a transport, administration still needs secrets, routes, and files. Those are later milestones, each with an acceptance list before implementation, none of them a license to copy every feature of another iOS terminal. Keychain-backed private keys, import and generation, passphrases, compatible algorithms, an explicit agent-forwarding policy, jump hosts, multiple hops with clear failures, configuration import that keeps secrets out of the shareable half. Then SFTP: a browser, Files integration, queues with progress and cancel, conflict review, no silent overwrite, no recursive delete as a default. Then the workday test: saved workspaces, gateway and direct coexisting, keyboard customization as justified, a compatibility matrix of real hosts, sustained daily acceptance. That last one is the bar again — absence of the other apps, not a settings count.

None of this is present tense. A Keychain screenshot in a lesson that says "you import a key" will fail the same review as a fake host-key dialog. Write them as destination. Keep today's "the phone does not receive private keys in continue-host-work" in the present, because that refusal is load-bearing until the key milestone actually ships.

Acceptance Before Implementation

Each milestone gets a concrete acceptance list first. That is how this family keeps a destination from becoming a vibe. "Jump hosts" is not done when a field exists. It is done when a named hop fails loudly, a secret does not leak into a log, and Dad can take the route he actually uses. "File transfer" is not done when a list of names draws. It is done when a conflict is a decision and a recursive delete is not a default.

The destination is the routes and files a real administration day needs, staged. Not every other app's extras. Not today's verbs wearing a future hat. Acceptance lists first. Implementation second. Present tense never.

Code

Later milestones, each a bar, none present·text
KEYS AND ROUTES (destination)
  Keychain-backed keys: import / generate / passphrase
  host key verify + changed-key refuse (pairs with direct SSH)
  agent-forwarding policy: explicit, default deny
  ProxyJump / multi-hop, failures named per hop
  config import/export with secrets separated

FILES (destination)
  SFTP browser + Files integration
  upload/download queues, cancel, resume where the protocol allows
  conflict review; no silent overwrite
  no recursive delete as a default
  jumps apply to transfers too — a hop is a hop

WORKDAY (destination)
  gateway and direct coexist
  saved workspaces
  retire the other iOS terminals for the actual jobs
  bar: absence, not a feature grid

PRESENT, until keys ship
  the phone does not receive or copy private keys
  SSH-through-the-Mac uses the Mac's key store

External links

Exercise

Pick one administration task you actually do (jump through a bastion, copy a log off a box, rotate a key). Write it as a destination acceptance line (what must be true, what must be loud when it fails). Then write the present-tense sentence that is true today instead ("the Mac still holds the keys; the phone is a surface"). If those two sentences could be swapped without anyone noticing, the tense is still mixed.
Hint
Acceptance is a failed hop you can point at, not a screenshot of a field. Today's honesty is the refusal to hold the secret yet.

Progress

Progress is local-only — sign in to sync across devices.
Spotted a bug or have feedback on this page?Report an Issue

Comments 0

🔔 Reply notifications (sign in)
Sign inPlease sign in to comment.

No comments yet — be the first.