feat: complete MQ-only dispatcher and OSS upload flow

This commit is contained in:
2026-09-22 21:09:06 +08:00
parent 704652bd0d
commit a2fcc4aabb
265 changed files with 18689 additions and 1469 deletions
+9 -14
View File
@@ -1,24 +1,19 @@
# Production physical-host example. Inject secrets and approved paths out of band.
# Physical-host example; real deployment requires separate authorization.
# Install dispatcher.json from deploys/config/dispatcher.json.example and replace
# its example dispatcher_id with this installation's unique stable UUID v4.
SIP_GO_AGENT_MODE=real
DISPATCHER_ID=dispatcher-primary
DISPATCHER_DB=/var/lib/sip-go-agent/dispatcher/dispatcher.db
RABBITMQ_EXCHANGE=agent-call.commands.v1
DISPATCHER_TENANT_KEY=<approved-original-tenant-key>
# RABBITMQ_URL=<injected-broker-url>
DISPATCHER_AGENT_ENDPOINTS_FILE=/etc/sip-go-agent/agent-endpoints.json
MTLS_CA_FILE=/etc/sip-go-agent/pki/ca.pem
MTLS_CERT_FILE=/etc/sip-go-agent/pki/dispatcher.pem
MTLS_KEY_FILE=/etc/sip-go-agent/pki/dispatcher.key
MTLS_SERVER_NAME=dispatcher.internal
# Single Dispatcher AgentControl gRPC listener. Agent facts and upload RPCs share it; Agents receive only presigned PUT grants.
DISPATCHER_GRPC_LISTEN=127.0.0.1:19443
DISPATCHER_ALLOWED_AGENT_IDS=agent-cell-a
DISPATCHER_OSS_REGION=cn-beijing
DISPATCHER_OSS_ENDPOINT=oss-cn-beijing-internal.aliyuncs.com
DISPATCHER_OSS_BUCKET=<injected-bucket>
DISPATCHER_OSS_KEY_PREFIX=agent-call/recordings
DISPATCHER_OSS_GRANT_TTL_SECONDS=900
DISPATCHER_OSS_MAX_ASSET_BYTES=67108864
DISPATCHER_OSS_ACCESS_KEY_ID_FILE=/etc/sip-go-agent/secrets/oss-access-key-id
DISPATCHER_OSS_ACCESS_KEY_SECRET_FILE=/etc/sip-go-agent/secrets/oss-access-key-secret
# DISPATCHER_CONTROL_LISTEN=127.0.0.1:18080
# DISPATCHER_CONTROL_TOKEN=<injected-secret>
# MTLS_PEER_CERT_FINGERPRINTS=<approved-agent-certificate-fingerprint>
# Inject only the credential variables explicitly referenced by dispatcher.json.
# Never put actual values in this example or commit them:
# GO_SIP_OSS_ACCESS_KEY_ID=<injected-at-runtime>
# GO_SIP_OSS_ACCESS_KEY_SECRET=<injected-at-runtime>
+5 -11
View File
@@ -1,12 +1,6 @@
# Offline/non-ECS OSS integration profile.
# Do not use this profile as the production ECS profile.
# Isolated non-production profile; not permission to access real OSS.
SIP_GO_AGENT_MODE=mock
DISPATCHER_OSS_REGION=cn-beijing
DISPATCHER_OSS_ENDPOINT=oss-cn-beijing.aliyuncs.com
DISPATCHER_OSS_BUCKET=<injected-offline-test-bucket>
DISPATCHER_OSS_KEY_PREFIX=agent-call/offline-recordings
DISPATCHER_OSS_GRANT_TTL_SECONDS=900
DISPATCHER_OSS_MAX_ASSET_BYTES=67108864
# Supply these through protected runtime files; never commit or log credentials.
DISPATCHER_OSS_ACCESS_KEY_ID_FILE=/run/secrets/oss-access-key-id
DISPATCHER_OSS_ACCESS_KEY_SECRET_FILE=/run/secrets/oss-access-key-secret
# OSS endpoint/bucket/prefix and credential references come only from the
# required --config JSON file. Inject its referenced credential variables via
# the controlled local test launcher; do not store keys in this example.
# Keep real egress blocked unless separately authorized.