The problem
Linux and GPU machines across several sites were reached through shared accounts. The goal was named access, and changes that can be traced from the request to the result on each machine.
What I did
- A dashboard and automation workflow connecting access requests to reviewed Git changes, Ansible execution and visible job results.
- Tailscale policies, named-user access, SSH configuration and sudo tiers.
- CI validation and revision checks before a change, and verification after it runs.
- Concurrency controls and failure-path regression tests.
Decisions
Record the intended state in Git
Every access change has a reviewed source.
Check the revision before execution
A change that moved after review is not applied.
Keep job states visible
Skipped, failed and unreachable hosts are shown, not hidden.
Verify the applied state
A job is finished only when the result is checked.
Boundaries
Design, implementation and review within a team, with AI-assisted development. The demo and illustrations are anonymised: no real hosts, topology, user counts or client details. Release and recovery work is described in project 10.