# TAPM Deployment Access TAPM Deployment Access is a short-lived authorization broker for protected deployment packages and installer actions. Technicians authenticate with Gitea, create a deployment code, and permit a limited number of hosts to use explicitly selected capabilities during a fixed authorization window. Default policy: - Public URL: `https://tapm.scity.us` - Authorization lifetime: 3 hours - Host limit: 3 - Authentication: Gitea OAuth - Shared state: MariaDB Galera - Package storage: private Gitea Generic Package Registry See [docs/deployment.md](docs/deployment.md) for installation and configuration. The ProxMenu integration contract is documented in [docs/client-api.md](docs/client-api.md). ## Components - `cmd/server`: portal, OAuth flow, authorization API, uploads, and downloads - `cmd/migrate`: ordered MariaDB schema migrations with an advisory lock - `internal/app`: application, security, and registry proxy logic - `deploy/nginx`: TLS reverse-proxy example - `compose.yaml`: hardened, host-networked container deployment ## Local checks ```sh docker run --rm -v "$PWD:/src" -w /src golang:1.24-alpine \ sh -c 'gofmt -w cmd internal && go test ./...' docker build -t tai/tapm-deployment-broker:local . ```