You need an authenticated
khal session with superadmin rights. Not sure? Run the mint command — a clear permission error tells you fast.1
Mint a single-use invite
@namastex.ai addresses only. Minting is what creates the engineer’s identity — there’s no account to set up first.2
Hand it off securely
Send it over a channel you’d trust with a password — not a public channel or an archived screenshot. It’s single-use: the engineer’s first
khal fde enroll consumes it.3
Approve their SSH lease
After they enroll and request a workstation, its SSH lease sits behind the Deploy Ledger until you approve it. Get their instance ID (from their
khal fde status), then approve through your khal fde admin tooling.No certificate authority — once approved, access is just the engineer’s own SSH key plus Tailscale.Your job is mint and approve. You don’t set passwords or certs (the engineer’s SSH key is the credential), pick a hostname (Tailscale does), or provision the VM (that’s the engineer’s
khal fde instance).🤖 Agent paste prompt
🤖 Agent paste prompt