Machine AuthorizationIndex
Machine authorization covers the credential and admission mechanisms that gate who and what can act on the platform — pairing a device onto the WireGuard mesh, issuing and rotating the Ed25519 capability tokens services use to authenticate to each other, enrolling a compute node into a fleet, and authenticating a signed binary download. These are genuinely separate mechanisms, not one system under different names; each guide states plainly where its own mechanism's real limits are, including where no revocation or un-pairing command exists today.
Start here: Pair a new device — registers a device with the pairing server and walks through administrator approval, the most common entry point into this category.
Pairing and tokens
- Pair a new device — register an os-console device and get it approved onto the WireGuard mesh
- Issue a capability token — mint an Ed25519-signed token and register it with a peer service
- Rotate keys and capability tokens — replace a credential within the system's real 24-hour expiry limits
Fleet enrollment
- Enroll a PPN node — start the per-node heartbeat agent and confirm it in the fleet controller
Software distribution
- Authenticate binary downloads — confirm an order and follow the signed download path for a release
Each guide carries its own prerequisites, verification steps, and rollback procedure; this page doesn't repeat them. Day-to-day operation of a running deployment is in How You Run It.
See also
- How You Run It — the remaining day-to-day operational guides
- Security and Trust — the identity and permissions model these mechanisms participate in
- Self-Hosting — deploying the appliances these credentials authenticate against