One private push server replaces public ntfy.sh topic-secrecy. Sessions page the phone as before — and the phone now steers any live tmux pane from anywhere. One new component; everything else is configuration.
1The Argument — two lanes, one server, least privilege
2Auth — three principals, no topic secrecy anywhere
Principal
Access
Lives
If it leaks
operator
read + write, all topics
phone app only
rotate; the only token that can steer panes
fleet-pub
write-only → alerts-*, hitl
nono profiles / Keychain
spam to your phone, nothing readable
fleet-sub
read-only → cmd-*
bridge daemon env
read your commands, can't publish or page
Rule #19 predicate: pane injection is MUTATING + PUBLIC → compensating control is real authentication (deny-all default, per-principal tokens, TLS). The old model — public ntfy.sh + secret topic names — is path obscurity and dies with this migration.
3What you type vs. what happens
PHONE → SESSION (new)
# in ntfy app, topic cmd-infra:"merge it and close the room"→ lands in wr-infra coordinator pane:Operator via ntfy: merge it and close the room
# prefix targets an agent pane:"hades: rotate the cal webhook secret"→ lands in wr-infra:0.1