EN · ORIGINAL REPOSITORY DOCUMENT
Deployment reference
Original English text. Commands and evidence apply to the revision and environment stated in the document.
product/licensing/deployment/README.md
Operator deployment templates
render.py produces a standalone nginx configuration, a Linux systemd service
and a deliberately unconfigured environment example. It never installs files,
creates accounts/keys/certificates, opens a listener or changes firewall settings.
Use Python 3.10+ to render files into a new directory for review:
python3 product/licensing/deployment/render.py \
--hostname licenses.operator.example \
--certificate /etc/letsencrypt/live/licenses.operator.example/fullchain.pem \
--private-key /etc/letsencrypt/live/licenses.operator.example/privkey.pem \
--runtime /srv/original-licensing --output /tmp/licensing-deployment-review
The template supports nginx 1.28+ with HTTPS, TLS 1.2/1.3 and SNI/Host matching. HTTP and unknown TLS names are refused rather than redirecting sensitive API requests. Only existing entitlement routes are proxied, with exact methods, 16-KiB request bodies, bounded upstream timeouts and no response caching. Unknown customer/admin/billing paths receive 404; administration stays local CLI under the operator’s Unix access controls. Download authorization and origin/installation ownership remain enforced by Go. Per-IP limits allow five requests/second with 20-request bursts; operators must size this for shared hosting/NAT workloads. No forwarded-IP trust is configured: adapting for another proxy requires an explicit trusted proxy configuration. Access logs are disabled and no request body or Authorization logging is configured.
/healthz is local-only at nginx. The Go loopback endpoint reports only ready or
unavailable, validates persisted state, and exposes no customer/license data.
Use it for local readiness monitoring; rate and latency monitoring, alert routing
and certificate-expiry monitoring still require an operator’s infrastructure.
Before installation the operator supplies a real DNS/certificate pair, a dedicated
original-licensing Unix identity and private runtime directories. The executable
and config are read-only to that service; only state/ is writable. Prepare an
existing validated state file rather than accidentally starting an empty restored
service. The systemd unit refuses a missing/empty state file. Put the HMAC material,
selected RSA key ID and package version in mode-0600 config/service.env, without
shell export prefixes; systemd’s EnvironmentFile is not a shell script. Put the
RSA private PEM and immutable reviewed ZIP in config/. The nginx certificate
key is separate from the Go entitlement signing key. Neither is distributed to
WordPress. Configure trusted HTTPS origin and public-key map in WordPress.
Review generated files using nginx -t -c /absolute/generated/nginx.conf and
systemd-analyze verify /absolute/generated/original-licensing.service on the
operator’s target host. Service installation/start, DNS, certificates, firewall,
monitoring and paid-provider setup remain external actions. This checkout does
not perform them. Linux systemd runtime confinement is not claimed proven by a
configuration syntax check; verify actual startup/readiness on the target host.
Follow backup and recovery, customer-operations and key rotation instructions before exposing any restored deployment. Recovery requires trusted latest records; templates cannot establish their freshness.
References: nginx HTTPS, request limits, and systemd execution.