Files
TA-Deployment-Broker/README.md
T
David Schroeder 943ddb064f initial upload
2026-07-25 13:11:37 -05:00

36 lines
1.2 KiB
Markdown

# TAPM Deployment Access
TAPM Deployment Access is a short-lived authorization broker for protected
deployment packages. Technicians authenticate with Gitea, create a deployment
code, and permit a limited number of hosts to download explicitly selected
packages during a fixed authorization window.
Default policy:
- Public URL: `https://tapm.scity.us`
- Authorization lifetime: 3 hours
- Host limit: 3
- Authentication: Gitea OAuth
- Shared state: MariaDB Galera
- Package storage: private Gitea Generic Package Registry
See [docs/deployment.md](docs/deployment.md) for installation and configuration.
The ProxMenu integration contract is documented in
[docs/client-api.md](docs/client-api.md).
## Components
- `cmd/server`: portal, OAuth flow, authorization API, and protected downloads
- `cmd/migrate`: ordered MariaDB schema migrations with an advisory lock
- `internal/app`: application, security, and registry proxy logic
- `deploy/nginx`: TLS reverse-proxy example
- `compose.yaml`: hardened, loopback-only container deployment
## Local checks
```sh
docker run --rm -v "$PWD:/src" -w /src golang:1.24-alpine \
sh -c 'gofmt -w cmd internal && go test ./...'
docker build -t tai/tapm-deployment-broker:local .
```