0ceb342d1491b0835f47c8b36a009cd3ed4f88b2
TAPM Deployment Access
TAPM Deployment Access is a short-lived authorization broker for protected deployment packages and installer actions. Technicians authenticate with Gitea, create a deployment code, and permit a limited number of hosts to use explicitly selected capabilities during a fixed authorization window.
Default policy:
- Public URL:
https://tapm.scity.us - Authorization lifetime: 3 hours
- Host limit: 3
- Authentication: Gitea OAuth
- Shared state: MariaDB Galera
- Package storage: private Gitea Generic Package Registry
See docs/deployment.md for installation and configuration. The ProxMenu integration contract is documented in docs/client-api.md.
Components
cmd/server: portal, OAuth flow, authorization API, uploads, and downloadscmd/migrate: ordered MariaDB schema migrations with an advisory lockinternal/app: application, security, and registry proxy logicdeploy/nginx: TLS reverse-proxy examplecompose.yaml: hardened, host-networked container deployment
Local checks
docker run --rm -v "$PWD:/src" -w /src golang:1.24-alpine \
sh -c 'gofmt -w cmd internal && go test ./...'
docker build -t tai/tapm-deployment-broker:local .
Description
Languages
Go
67.9%
Shell
12.8%
HTML
11.3%
CSS
6.5%
JavaScript
1.1%
Other
0.4%