This repository manages organizational SSH and WireGuard public keys using a centralized, Git-based workflow.
The goal is to eliminate:
All access requests are handled through Pull Requests (PRs), ensuring full visibility and controlled approvals.
This repository stores:
Only public keys are stored here.
❗ Private keys must NEVER be committed to this repository.
infra-access-control/
│
├── ssh/
│ ├── production/
│ │ ├── admins/
│ │ ├── developers/
│ │ └── readonly/
│ │
│ └── staging/
│ ├── admins/
│ └── developers/
│
├── wireguard/
│ ├── production/
│ └── staging/
│
└── README.md
ssh-keygen -t ed25519 -C "firstname.lastname@company.com"
Public key:
~/.ssh/id_ed25519.pub
git clone git@github.com:<org>/infra-access-control.git
cd infra-access-control
git checkout -b add-firstname-lastname-ssh
Place file in correct directory:
Example:
ssh/production/developers/firstname.lastname.pub
git add .
git commit -m "Add SSH key for firstname lastname (production developer)"
git push origin add-firstname-lastname-ssh
Open a Pull Request in GitHub.
Access is granted only after PR approval and merge.
wg genkey | tee privatekey | wg pubkey > publickey
Only the public key is submitted.
Place file in:
wireguard/production/firstname.lastname.wg.pub
Submit via branch + Pull Request.
No keys are sent via email.
main.All changes remain auditable in Git history.
main are disabled.ed25519.SSH key file:
firstname.lastname.pub
WireGuard key file:
firstname.lastname.wg.pub
Filenames must match Linux usernames where applicable.
This repository provides a secure, centralized, and auditable method for managing SSH and WireGuard public keys without relying on insecure communication channels.
All access is controlled through a structured Pull Request workflow.