36 lines
1.2 KiB
Markdown
36 lines
1.2 KiB
Markdown
# TAPM Deployment Access
|
|
|
|
TAPM Deployment Access is a short-lived authorization broker for protected
|
|
deployment packages. Technicians authenticate with Gitea, create a deployment
|
|
code, and permit a limited number of hosts to download explicitly selected
|
|
packages during a fixed authorization window.
|
|
|
|
Default policy:
|
|
|
|
- Public URL: `https://tapm.scity.us`
|
|
- Authorization lifetime: 3 hours
|
|
- Host limit: 3
|
|
- Authentication: Gitea OAuth
|
|
- Shared state: MariaDB Galera
|
|
- Package storage: private Gitea Generic Package Registry
|
|
|
|
See [docs/deployment.md](docs/deployment.md) for installation and configuration.
|
|
The ProxMenu integration contract is documented in
|
|
[docs/client-api.md](docs/client-api.md).
|
|
|
|
## Components
|
|
|
|
- `cmd/server`: portal, OAuth flow, authorization API, and protected downloads
|
|
- `cmd/migrate`: ordered MariaDB schema migrations with an advisory lock
|
|
- `internal/app`: application, security, and registry proxy logic
|
|
- `deploy/nginx`: TLS reverse-proxy example
|
|
- `compose.yaml`: hardened, loopback-only container deployment
|
|
|
|
## Local checks
|
|
|
|
```sh
|
|
docker run --rm -v "$PWD:/src" -w /src golang:1.24-alpine \
|
|
sh -c 'gofmt -w cmd internal && go test ./...'
|
|
docker build -t tai/tapm-deployment-broker:local .
|
|
```
|