ab9d9301f0
seedDirectory() only ever linked ONE OAuth client -- whatever id was passed in, which was always the proxy's (resolvedClientId). jump-host's own OAuth client (minted by provisionJumpHost) was never passed through, so it was created but never got a ResourceEdge to the "SSH Jump Host" service resource -- it just showed up in the Directory with no parent. provisionJumpHost now returns the jump client's id (looking it up even on the "already configured" early-return path, so existing deployments self-heal on the next setup.sh run instead of needing this fixed only for fresh installs), and seedDirectory takes it as a third argument, linking it under the jump-host service the same way the proxy's client is linked under the proxy service. Also fixed live on the affected deployment via the directory-admin API (created the missing edge directly) rather than waiting for a rebuild. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>