Route Agent CLI through isolated approved Mock runtime

This commit is contained in:
2026-09-30 06:59:06 +08:00
parent 99f8f5d721
commit 07850076e3
7 changed files with 411 additions and 29 deletions
+17 -15
View File
@@ -1,18 +1,20 @@
# Production physical-host example. Inject secrets and approved paths out of band.
SIP_GO_AGENT_MODE=real
AGENT_ID=agent-cell-a
AGENT_VERSION=0.1.0-p1.20260919
CELL_ID=cell-a
AGENT_SPOOL=/var/lib/sip-go-agent/agent/spool
AGENT_GRPC_LISTEN=0.0.0.0:19090
# Isolated local Mock only. This is not a production or real-call configuration.
# A non-production validation host still requires the mandatory native Asterisk
# and capture-first diagnostics in deploys/test/nonprod-call-evidence.sh.
# Start explicitly: sip-go-agent agent --mode mock
AGENT_ID=agent-mock
CELL_ID=cell-mock
AGENT_GRPC_LISTEN=127.0.0.1:19090
AGENT_SESSION_PATH=/var/lib/sip-go-agent/agent/session.json
# Pre-create this directory with mode 0700; neither state nor files are cleared.
AGENT_RECOVERY_ROOT=/var/lib/sip-go-agent/agent/recovery
DISPATCHER_GRPC_ENDPOINT=127.0.0.1:19443
DISPATCHER_GRPC_SERVER_NAME=dispatcher.local
MTLS_CA_FILE=/etc/sip-go-agent/pki/ca.pem
MTLS_CERT_FILE=/etc/sip-go-agent/pki/agent.pem
MTLS_KEY_FILE=/etc/sip-go-agent/pki/agent.key
MTLS_SERVER_NAME=agent-cell-a.internal
# Approved Dispatcher management address; upload data goes Agent -> OSS directly.
# DISPATCHER_GRPC_ENDPOINT=<dispatcher-management-address>:19443
# DISPATCHER_GRPC_SERVER_NAME=dispatcher.internal
DISPATCHER_AGENT_ENDPOINTS_FILE=/etc/sip-go-agent/agent-endpoints.json
AGENT_STATIC_ARTIFACT=/etc/sip-go-agent/artifacts/cell-a.json
AGENT_CALL_BUSINESS_LOG=/var/lib/sip-go-agent/agent/call-business.jsonl
# AGENT_CALL_PHONE_LOG_KEY=<injected-secret-at-least-16-bytes>
# Required: SHA-256 fingerprint of the approved Dispatcher's certificate.
# MTLS_PEER_CERT_FINGERPRINTS=<injected-64-character-hex-fingerprint>
# Synthetic fixtures only; applied SIP revisions do not prove Asterisk loaded them.
AGENT_MOCK_SCENARIO_FILE=/etc/sip-go-agent/mock/scenario.json
AGENT_MOCK_APPLIED_SIP_FILE=/etc/sip-go-agent/mock/applied-sip.json