S27: deploy creates npe-dir endpoint keys and systemd KEYDIR
Some checks are pending
review / inventory (push) Waiting to run
Some checks are pending
review / inventory (push) Waiting to run
This commit is contained in:
parent
185cdaabdb
commit
548d9967d5
3 changed files with 46 additions and 1 deletions
|
|
@ -115,6 +115,15 @@ After a context reset: read this file, then `Remaining-Work.MD`.
|
|||
- PDFs link to **sibling PDFs** (`nats-service-endpoints.pdf`, `secure-messaging.pdf`, `peergos-for-compliance.pdf`) — no `.md` hrefs.
|
||||
- Controls / custody / variables chapters in the system PDF.
|
||||
|
||||
## S27 NPE/HPKE content + public-key directory
|
||||
|
||||
- Content: HPKE-Base only. sm-leaf rejects ``lab-xor`` / ``plain-lab``.
|
||||
- Directory: ``/opt/pfc/etc/npe-dir`` public JSON + private 0600.
|
||||
``GET /v1/npe/keys`` lists public keys for every E2E service.
|
||||
- Clear on NATS: routing + error codes only. Content never in JSON.
|
||||
- WAN NATS 4222 remains token-gated public-edge (not open). PFC uses
|
||||
internal ``10.10.10.21:4222``.
|
||||
|
||||
Go `pfc-repl` now serves loopback `GET 127.0.0.1:18784/health`; admin `PFC_REPL_URL` points there. Ingest replicas a/b do not bind HTTP.
|
||||
|
||||
## Do not
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue