I’m a single user and my authorized_keys is 25 lines. I have different yubikeys in laptops, keys on iPads and iPhones, and secure enclave keys on macs.
I imagine starlink has more than 1-2 sysadmins. I think a hundred pubkeys would be reasonable.
I imagine starlink has more than 1-2 sysadmins. I think a hundred pubkeys would be reasonable.
Having some way to remotely push updates, and having some kinda of (preferably with your consent!) remote access might be reasonable, but I would expect that to be via some kind of intermediate gateway/app/something and not direct from a sysadmin’s individual account.
I imagine the most ideal situation would be 1) minimising the number keys, 2) use hardware backed authentication or certificate based authentication, 3) lock up the private keys somewhere safe.
The idea of 41 points of failure that can SSH into any starlink terminal is not appealing.