2.8 KiB
Local deployment draft
Production packaging is under ../deploys/. This directory contains only the standalone project's local/mock entry points.
It is not the W13 frozen production candidate: G0, external authority, real broker/OSS/SIP/AI
verification, and the two-Cell acceptance gates remain blocked. W01/W02 Proto and
local Agent RPC/mTLS tests are present in the project.
Mock smoke run
From the project root:
make check
SIP_GO_AGENT_MODE=mock AGENT_SPOOL=./spool ./dist/sip-go-agent agent
SIP_GO_AGENT_MODE=mock DISPATCHER_DB=./dispatcher.db ./dist/sip-go-agent dispatcher
For an isolated Dispatcher-to-Agent mTLS startup check, provide a strict Dispatcher-owned endpoint inventory and the deployment mTLS files:
SIP_GO_AGENT_MODE=mock \
DISPATCHER_DB=./dispatcher.db \
DISPATCHER_AGENT_ENDPOINTS_FILE=./configs/agent-endpoints.example.json \
# Optional Agent-side allowlist: export MTLS_PEER_CERT_FINGERPRINTS=<dispatcher-leaf-sha256>
MTLS_CA_FILE=/path/to/ca.pem MTLS_CERT_FILE=/path/to/dispatcher.pem \
MTLS_KEY_FILE=/path/to/dispatcher.key \
./dist/sip-go-agent dispatcher
The Dispatcher probes each configured Agent, binds its returned boot ID, and activates a session before continuing. Endpoint identity is deployment-owned; no tenant command can select an address or certificate. This check is still mock/isolated and does not constitute two-Cell, production health, or P1 acceptance.
make release creates a local-development binary, module copies, SHA-256
checksums, and a manifest. The manifest preserves a dirty-source marker and
must not be treated as a production candidate until W08–W12 integration and a
clean reproducible build are complete.
The mock run creates no cloud resource, real call, or external callback. To run a
local Agent RPC listener, set AGENT_GRPC_LISTEN and deployment-provided
MTLS_CA_FILE/MTLS_CERT_FILE/MTLS_KEY_FILE; a real Agent additionally
requires AGENT_STATIC_ARTIFACT pointing to the management-approved immutable
Cell artifact; the server requires TLS 1.3,
client certificates and a SAN. A real Dispatcher run must receive broker
credentials through a controlled environment; never put them in this repository.
Production deployment boundary
Use deploys/build-package.sh and the version-locked physical systemd package for production. Do not use this directory's mock commands or Docker Compose as a production deployment.
Runtime boundaries
- Dispatcher owns the SQLite file and runs as one active process.
- Agent owns its
AGENT_SPOOLdirectory and has no business database. - Production services must run as a non-root service account (the deployment
baseline is
rogee), with separate DB/spool directories and restricted file permissions. - Do not enable real mode until the W01/W02/W04 and supplier authorization evidence is recorded.