A legacy login credential was printed in a previously public README revision. The current documentation removes the value, but documentation cleanup does not revoke access.
Security work:
- identify every installation and account for which the former credential may still work
- rotate or disable password login through an approved recovery path
- prefer verified key-only or tailnet-scoped access where compatible with field recovery
- confirm access with a fresh remote login before ending any rollback window
- store replacement credentials only in the approved password manager
Acceptance criteria:
- the former credential no longer authenticates anywhere in scope
- at least one approved recovery path is verified per live installation
- no credential values are posted to this issue, repository, logs, or screenshots
- NETWORKING.md and RECOVERY.md describe credential retrieval without embedding secrets.
A legacy login credential was printed in a previously public README revision. The current documentation removes the value, but documentation cleanup does not revoke access.
Security work:
Acceptance criteria: