nats-service-endpoints/source/index.rst

29 lines
912 B
ReStructuredText

NATS Service Endpoints
======================
Canonical catalog for Verae / PFC / secure-messaging on
https://git.georgelambert.org/marchon/nats-service-endpoints
The NATS broker is **untrusted**. Production E2E is NPE (HPKE). Lab may use
``pfc-lab-xor``. This is **not** a HIPAA/SOC 2/ISO certificate.
Related: `system-git-sync <https://git.georgelambert.org/marchon/system-git-sync>`_,
`secure-messaging <https://git.georgelambert.org/marchon/secure-messaging>`_,
`peergos-for-compliance <https://git.georgelambert.org/marchon/peergos-for-compliance>`_.
.. toctree::
:maxdepth: 2
passthrough
endpoints
errors
config
tracing
Passthrough
-----------
Destination mailbox id and the NATS subject may be in the clear so routers
can work. The **body** is ciphertext. After send, the sender cannot open
that ciphertext; they keep a ``lookup_id`` only. The same rule applies to
the responder.