Removing a key closes its connections.
- The store announces committed revocations (
RemoveSSHKey,RemoveDeployKey,SetUserDisabledon disable,DeleteUser) and answers which key ids are live (LiveSSHKeys). - sshd records the key and user on each connection. A revocation cuts every matching connection; a 15 s sweep catches revocations made by another process (
gitbayd adminon the host). - Every exec and every git transport session re-reads its key: removed, moved to another account, or re-scoped takes effect on the next command. Scope and audit source come from the fresh read.
gitutil.Transporttakes a cancel channel and kills git's process group; a push killed before pre-receive answers moves no ref.- e2e: an OpenSSH ControlMaster holds a receive-pack open mid-pack, the key is removed, the push dies, the master is gone and
mainhas not moved. - Threat-Model, Users and Architecture pages; #256 leaves Known-Gaps; CHANGELOG.
Removing the key the current session uses cuts that session after the removal commits. System ssh mode applies the per-exec check but does not cut a running forced-command process.
First MR of the credentials stack (plan docs/plans/2026-09-27-credentials-and-sessions.md).
Closes #256