Archived
Assert the closed session-to-root paths on an installed system — no blanket input-group membership, no shipped asdcontrol sudoers grant — and exercise omarchy-setup-security-sshd unattended end to end: sshd up, key authorized, password and keyboard-interactive authentication off in the effective config, SSH port rate limited in the firewall. The sshd section mutates the machine, so it requires the explicit OMARCHY_ACCEPTANCE_SUDO_PASSWORD opt-in that omarchy-iso-test passes for its throwaway VMs; elsewhere it skips.