Commit graph

4 commits

Author SHA1 Message Date
088e920f9d fix(bastion): match OpenSSH username parsing for protocol-proxy hop
OpenSSH treats the last @ as user/host separator, so the SSH username must be hop@target@ip without duplicating hop_host. Legacy templates with {hop_host} are stripped automatically; connect logs now show bastion_ssh_cli for comparison with manual ssh.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:49:43 +08:00
79ae5ff31c fix(bastion): use keyboard-interactive auth for protocol-proxy bastions
ZTE-TSM and similar bastions reject standard SSH password auth and require Vault password via keyboard-interactive; connect over an authenticated Paramiko session instead of re-handshaking with Netmiko.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:31:46 +08:00
bac4a609b1 docs(managed-ne): use placeholder IPs in bastion hop examples
Replace real site addresses with 1.1.1.1/2.2.2.2 and generic usernames in i18n hints and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:59:32 +08:00
d3d7f62a02 feat(managed-ne): add bastion SSH protocol proxy hop type
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:47:52 +08:00