Files
go-sip/deploys/cell/README.md
T

44 lines
2.7 KiB
Markdown

# Physical Asterisk Cell input
The production Cell is physical-host business software managed by the approved
SIP management release, not a Docker service and not a Go Agent subprocess.
Asterisk and the SIP Agent are the only business-code services in this project;
MQ, OSS, AI and SaaS APIs remain externally supplied infrastructure.
The pinned source input is:
- Asterisk `22.10.1`
- Git commit `f0e408a7b0d829c85bf15fa4b487870a50cb3000`
- Archive `../packages/asterisk-22.10.1-source.tar.gz`
- SHA-256 `373c98f4d4a1b923b42def0aee03f4e36aca9d1c244a8eeda646da8a97f89663`
`build-asterisk-native.sh` reproduces the stage from the pinned source and
local dependency cache; the build selects no downloaded core sounds/MOH.
The native package includes its `build-platform` marker and
`install-asterisk-user.sh`. Run that installer as `rogee`, never as root;
it verifies the stage hash and required libraries, installs into `~/.local/opt/`,
sets up `~/.config/go-sip-asterisk/` without overwriting existing files, and
installs `go-sip-asterisk.service` under `systemd --user`. Production requires
`loginctl enable-linger rogee` and a verified reboot-persistent `enabled+active`
service; `--nonprod` allows a session-scoped Debian 12 native build but does
not certify reboot persistence. The management-approved static `pjsip.conf`,
ARI and RTP configuration must be supplied separately. For the isolated
nonproduction user service only, `configure-asterisk-user-ari.sh` creates
private `ari.conf`, loopback-only `http.conf` and an owner-only `ari-secret`
without printing credentials, overwriting existing files or restarting the
service. Restart the user service only after separately verifying zero active
calls, then read back ARI HTTP and both `enabled`/`active` state. Do not treat
this local test setup as a management-approved production configuration.
The bundled stage has no live SIP trunk or dialing authorization; verify loaded endpoints and contacts
before any call. Do not substitute another Asterisk version or a container image.
The Go Agent package only consumes the resulting approved Cell artifact and
reports its applied revision. Local Mock fixtures do not prove real services.
Before every real outbound attempt, the operator must obtain a fresh user
confirmation in the current conversation that names the SIP channel, raw target
number and capture plan. Real SIP outbound calls are permitted only from 09:00
(inclusive) through 20:00 (exclusive), Asia/Shanghai time; outside that window
the Agent/Dispatcher must fail closed rather than wait, retry, delay or switch
trunks. A prior confirmation does not authorize retries or additional targets;
failed calls must stop for a new confirmation.