db2db5095b
Regression guard for bootstrap.js's jump-secrets.js template: its ldap block must use ldaps:// (implicit TLS, :636), not ldap:// (:389), as long as tlsOptions is set alongside it. ldapts treats a non-empty tlsOptions as "use implicit TLS" regardless of URL scheme, and jump-host's LDAP client always sets tlsOptions -- so this exact combination broke every SSH login to jump-host (any account, any password) before being root-caused against a real deployment. Static (parses bootstrap.js as text), not a require()+exec of it -- bootstrap.js is a self-running provisioning script with real side effects (LDAP writes, live API calls), not a library, so there's nothing safe to import and call in CI. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>