feat: complete MQ-only dispatcher and OSS upload flow
This commit is contained in:
Vendored
+9
-14
@@ -1,24 +1,19 @@
|
||||
# Production physical-host example. Inject secrets and approved paths out of band.
|
||||
# Physical-host example; real deployment requires separate authorization.
|
||||
# Install dispatcher.json from deploys/config/dispatcher.json.example and replace
|
||||
# its example dispatcher_id with this installation's unique stable UUID v4.
|
||||
SIP_GO_AGENT_MODE=real
|
||||
DISPATCHER_ID=dispatcher-primary
|
||||
DISPATCHER_DB=/var/lib/sip-go-agent/dispatcher/dispatcher.db
|
||||
RABBITMQ_EXCHANGE=agent-call.commands.v1
|
||||
DISPATCHER_TENANT_KEY=<approved-original-tenant-key>
|
||||
# RABBITMQ_URL=<injected-broker-url>
|
||||
DISPATCHER_AGENT_ENDPOINTS_FILE=/etc/sip-go-agent/agent-endpoints.json
|
||||
MTLS_CA_FILE=/etc/sip-go-agent/pki/ca.pem
|
||||
MTLS_CERT_FILE=/etc/sip-go-agent/pki/dispatcher.pem
|
||||
MTLS_KEY_FILE=/etc/sip-go-agent/pki/dispatcher.key
|
||||
MTLS_SERVER_NAME=dispatcher.internal
|
||||
# Single Dispatcher AgentControl gRPC listener. Agent facts and upload RPCs share it; Agents receive only presigned PUT grants.
|
||||
DISPATCHER_GRPC_LISTEN=127.0.0.1:19443
|
||||
DISPATCHER_ALLOWED_AGENT_IDS=agent-cell-a
|
||||
DISPATCHER_OSS_REGION=cn-beijing
|
||||
DISPATCHER_OSS_ENDPOINT=oss-cn-beijing-internal.aliyuncs.com
|
||||
DISPATCHER_OSS_BUCKET=<injected-bucket>
|
||||
DISPATCHER_OSS_KEY_PREFIX=agent-call/recordings
|
||||
DISPATCHER_OSS_GRANT_TTL_SECONDS=900
|
||||
DISPATCHER_OSS_MAX_ASSET_BYTES=67108864
|
||||
DISPATCHER_OSS_ACCESS_KEY_ID_FILE=/etc/sip-go-agent/secrets/oss-access-key-id
|
||||
DISPATCHER_OSS_ACCESS_KEY_SECRET_FILE=/etc/sip-go-agent/secrets/oss-access-key-secret
|
||||
# DISPATCHER_CONTROL_LISTEN=127.0.0.1:18080
|
||||
# DISPATCHER_CONTROL_TOKEN=<injected-secret>
|
||||
# MTLS_PEER_CERT_FINGERPRINTS=<approved-agent-certificate-fingerprint>
|
||||
# Inject only the credential variables explicitly referenced by dispatcher.json.
|
||||
# Never put actual values in this example or commit them:
|
||||
# GO_SIP_OSS_ACCESS_KEY_ID=<injected-at-runtime>
|
||||
# GO_SIP_OSS_ACCESS_KEY_SECRET=<injected-at-runtime>
|
||||
|
||||
+5
-11
@@ -1,12 +1,6 @@
|
||||
# Offline/non-ECS OSS integration profile.
|
||||
# Do not use this profile as the production ECS profile.
|
||||
# Isolated non-production profile; not permission to access real OSS.
|
||||
SIP_GO_AGENT_MODE=mock
|
||||
DISPATCHER_OSS_REGION=cn-beijing
|
||||
DISPATCHER_OSS_ENDPOINT=oss-cn-beijing.aliyuncs.com
|
||||
DISPATCHER_OSS_BUCKET=<injected-offline-test-bucket>
|
||||
DISPATCHER_OSS_KEY_PREFIX=agent-call/offline-recordings
|
||||
DISPATCHER_OSS_GRANT_TTL_SECONDS=900
|
||||
DISPATCHER_OSS_MAX_ASSET_BYTES=67108864
|
||||
# Supply these through protected runtime files; never commit or log credentials.
|
||||
DISPATCHER_OSS_ACCESS_KEY_ID_FILE=/run/secrets/oss-access-key-id
|
||||
DISPATCHER_OSS_ACCESS_KEY_SECRET_FILE=/run/secrets/oss-access-key-secret
|
||||
# OSS endpoint/bucket/prefix and credential references come only from the
|
||||
# required --config JSON file. Inject its referenced credential variables via
|
||||
# the controlled local test launcher; do not store keys in this example.
|
||||
# Keep real egress blocked unless separately authorized.
|
||||
|
||||
Reference in New Issue
Block a user