Back to the main page
AGENTS.md for Windows project in Codex
C:\Users\zdudic\Documents\Windows\AGENTS.md
I have Codex installed in Windows Pro 11 system, this is Agent for Windows project:
file C:\Users\zdudic\Documents\Windows\AGENTS.md
The project in general involves SSH to remote Windows host and doing some work there.
# Runbook for SSH to Remote Windows Servers
## Purpose
This workspace is for working with remote Windows servers through the approved access path:
Zarko's Windows laptop -> trusted.domain.com -> svc-account -> Windows server
Zarko provides the target host and task for each session.
Use PowerShell unless the task specifically requires `cmd.exe`.
## Important General Rules
* Prefer read-only checks and safe diagnostics before making changes.
* Do not print passwords, private keys, API tokens, or other secrets. It is OK
to list key filenames, public-key fingerprints, and non-sensitive diagnostics.
* Use non-interactive flags where they are supported so a command fails rather
than hangs at a prompt.
* Do not bypass a changed SSH host key. Report the host, fingerprint, and the
relevant known-hosts entry to Zarko.
* Before rebooting a host; changing services, Windows Firewall, networking,
WinRM, SSH, user or group access, security policy, or registry settings; ask
Zarko for approval.
* Once connected to a target, pause for Zarko's task instructions before making
any change.
*
## Remote Access Method
Use SSH with PowerShell as the default method for remote Windows work. It is
non-interactive, reproducible, and leaves Zarko's local Windows desktop usable.
Use RDC only when a task genuinely requires the Windows graphical interface.
Starting an RDC session manually does not itself reserve the desktop. However,
when Codex uses Computer Use to control an RDC window, it runs on the active
Windows desktop and takes foreground keyboard and pointer input. Zarko may be
unable to use other local applications until the task is stopped or control is
taken back.
Do not start Computer Use or control an RDC session unless Zarko explicitly
requests GUI control and accepts that the local desktop is reserved for that
task. Stop or pause immediately when Zarko takes control. For long-running GUI
work, recommend a separate Windows VM or device rather than Zarko's primary
laptop.
## First Hop: Zarko's Windows Laptop to trusted.domain.com
Key directory:
C:\\\\Zarko\\\\SSH\_bin\\\\ssh\_keys
Trusted jump host:
trusted.domain.com
Login account:
zdudic@trusted.domain.com
Working PuTTY private key:
C:\\\\Zarko\\\\SSH\_bin\\\\ssh\_keys\\\\rsa-key-3k.ppk
The first hop pins the SHA-256 fingerprint of the jump host's Ed25519 SSH host
public key (`/etc/ssh/ssh\_host\_ed25519\_key.pub` on trusted.domain.com):
SHA256:abc123...123
Run the first hop from the local Windows command environment:
cmd.exe /d /s /c 'plink -batch -no-antispoof -hostkey "SHA256:abc123...123" zdudic@trusted.domain.com -i "C:\\\\Zarko\\\\SSH\_bin\\\\ssh\_keys\\\\rsa-key-3k.ppk" "REMOTE\_COMMAND"'
`-batch` prevents password prompts, `-no-antispoof` suppresses PuTTY's
interactive access banner, and `-hostkey` verifies the intended jump host
without depending on PuTTY's host-key cache.
## Second Hop: trusted.domain.com to the Windows Server
On trusted.domain.com, use the `svc-account` account for access to Windows hosts:
sudo su - svc-account
This step requires a TTY. When running it through Plink, add `-t` to the Plink
command. Do not change the sudo policy to work around a TTY requirement; report
an unexpected failure to Zarko.
From the `svc-account` session, connect to the target Windows host provided by Zarko:
ssh TARGET\_WINDOWS\_HOST
Example:
ssh some-win-host
The expected remote shell is Windows PowerShell. Use `cmd` only when a task
requires the Windows command interpreter.
If SSH reports an unknown or changed target-host key, stop and ask Zarko to
verify it. Do not use `StrictHostKeyChecking=no` as a workaround.
The message below can appear before a successful Windows connection because SSH
tries the default `svc-account` RSA key before using the working authentication path:
load pubkey "/home/svc-account/.ssh/id_rsa": Invalid key length
Do not modify SSH key files to suppress this message. Treat it as non-blocking
only when the connection subsequently succeeds; otherwise report it to Zarko.
## Working on Windows Hosts
* Work as `svc-account` by default. `svc-account` is a member of the local
Administrators group on the managed Windows hosts. Do not use a direct
Administrator or SYSTEM session unless Zarko explicitly requests it.
* Windows does not use `sudo`; never attempt to run `sudo` on a Windows target.
* Administrators-group membership does not necessarily mean that the remote
PowerShell session has an elevated UAC token. Before an administrative task,
check the effective identity and privileges with non-modifying commands such as
`whoami /groups`. If elevation is required, do not bypass UAC or alter its
policy; ask Zarko for the approved method.
* When a command can change state, explain the intended effect before running
it and use the narrowest practical scope.
* If an administrative action requires interactive confirmation or credentials,
do not try to bypass that requirement. Ask Zarko how to proceed.
*
## Troubleshooting
If Plink hangs, confirm that `-batch` and `-no-antispoof` are present.
If the first-hop host-key check fails, stop and verify the new fingerprint with
Zarko before changing the pinned value.
If access to a Windows target fails, capture the hostname, account, exact SSH
or PowerShell error, and the non-sensitive connection details. Do not alter
Windows access controls, SSH configuration, WinRM, or firewall rules without
approval.
## Work Log
Maintain `WORKLOG.md` in this project with commands run, findings, changes,
and follow-up actions. Never record secrets.
Back to the main page