initial upload
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
# TAPM Deployment Access
|
||||
|
||||
TAPM Deployment Access is a short-lived authorization broker for protected
|
||||
deployment packages. Technicians authenticate with Gitea, create a deployment
|
||||
code, and permit a limited number of hosts to download explicitly selected
|
||||
packages during a fixed authorization window.
|
||||
|
||||
Default policy:
|
||||
|
||||
- Public URL: `https://tapm.scity.us`
|
||||
- Authorization lifetime: 3 hours
|
||||
- Host limit: 3
|
||||
- Authentication: Gitea OAuth
|
||||
- Shared state: MariaDB Galera
|
||||
- Package storage: private Gitea Generic Package Registry
|
||||
|
||||
See [docs/deployment.md](docs/deployment.md) for installation and configuration.
|
||||
The ProxMenu integration contract is documented in
|
||||
[docs/client-api.md](docs/client-api.md).
|
||||
|
||||
## Components
|
||||
|
||||
- `cmd/server`: portal, OAuth flow, authorization API, and protected downloads
|
||||
- `cmd/migrate`: ordered MariaDB schema migrations with an advisory lock
|
||||
- `internal/app`: application, security, and registry proxy logic
|
||||
- `deploy/nginx`: TLS reverse-proxy example
|
||||
- `compose.yaml`: hardened, loopback-only container deployment
|
||||
|
||||
## Local checks
|
||||
|
||||
```sh
|
||||
docker run --rm -v "$PWD:/src" -w /src golang:1.24-alpine \
|
||||
sh -c 'gofmt -w cmd internal && go test ./...'
|
||||
docker build -t tai/tapm-deployment-broker:local .
|
||||
```
|
||||
Reference in New Issue
Block a user