2026-07-25 19:17:00 -05:00
2026-07-25 14:51:48 -05:00
2026-07-25 14:55:41 -05:00
2026-07-25 18:42:09 -05:00
2026-07-25 18:42:09 -05:00
2026-07-25 18:42:09 -05:00
2026-07-25 13:11:37 -05:00
2026-07-25 18:42:09 -05:00
2026-07-25 13:11:37 -05:00
2026-07-25 16:18:38 -05:00
2026-07-25 13:11:37 -05:00
2026-07-25 13:11:37 -05:00
2026-07-25 13:11:37 -05:00
2026-07-25 14:51:48 -05:00
2026-07-25 19:17:00 -05:00

TAPM Deployment Access

TAPM Deployment Access is a short-lived authorization broker for protected deployment packages and installer actions. Technicians authenticate with Gitea, create a deployment code, and permit a limited number of hosts to use explicitly selected capabilities during a fixed authorization window.

Default policy:

  • Public URL: https://tapm.scity.us
  • Authorization lifetime: 3 hours
  • Host limit: 3
  • Authentication: Gitea OAuth
  • Shared state: MariaDB Galera
  • Package storage: private Gitea Generic Package Registry

See docs/deployment.md for installation and configuration. The ProxMenu integration contract is documented in docs/client-api.md.

Components

  • cmd/server: portal, OAuth flow, authorization API, uploads, and downloads
  • cmd/migrate: ordered MariaDB schema migrations with an advisory lock
  • internal/app: application, security, and registry proxy logic
  • deploy/nginx: TLS reverse-proxy example
  • compose.yaml: hardened, host-networked container deployment

Local checks

docker run --rm -v "$PWD:/src" -w /src golang:1.24-alpine \
  sh -c 'gofmt -w cmd internal && go test ./...'
docker build -t tai/tapm-deployment-broker:local .
S
Description
No description provided
Readme
178 KiB
Languages
Go 62%
Shell 16.2%
HTML 12.2%
CSS 7.9%
JavaScript 1.2%
Other 0.5%