Private release previewNo live purchasesRelease details ↗

EN · ORIGINAL REPOSITORY DOCUMENT

Deployment reference

Original English text. Commands and evidence apply to the revision and environment stated in the document.

product/licensing/deployment/README.md

Operator deployment templates

render.py produces a standalone nginx configuration, a Linux systemd service and a deliberately unconfigured environment example. It never installs files, creates accounts/keys/certificates, opens a listener or changes firewall settings. Use Python 3.10+ to render files into a new directory for review:

python3 product/licensing/deployment/render.py \
  --hostname licenses.operator.example \
  --certificate /etc/letsencrypt/live/licenses.operator.example/fullchain.pem \
  --private-key /etc/letsencrypt/live/licenses.operator.example/privkey.pem \
  --runtime /srv/original-licensing --output /tmp/licensing-deployment-review

The template supports nginx 1.28+ with HTTPS, TLS 1.2/1.3 and SNI/Host matching. HTTP and unknown TLS names are refused rather than redirecting sensitive API requests. Only existing entitlement routes are proxied, with exact methods, 16-KiB request bodies, bounded upstream timeouts and no response caching. Unknown customer/admin/billing paths receive 404; administration stays local CLI under the operator’s Unix access controls. Download authorization and origin/installation ownership remain enforced by Go. Per-IP limits allow five requests/second with 20-request bursts; operators must size this for shared hosting/NAT workloads. No forwarded-IP trust is configured: adapting for another proxy requires an explicit trusted proxy configuration. Access logs are disabled and no request body or Authorization logging is configured.

/healthz is local-only at nginx. The Go loopback endpoint reports only ready or unavailable, validates persisted state, and exposes no customer/license data. Use it for local readiness monitoring; rate and latency monitoring, alert routing and certificate-expiry monitoring still require an operator’s infrastructure.

Before installation the operator supplies a real DNS/certificate pair, a dedicated original-licensing Unix identity and private runtime directories. The executable and config are read-only to that service; only state/ is writable. Prepare an existing validated state file rather than accidentally starting an empty restored service. The systemd unit refuses a missing/empty state file. Put the HMAC material, selected RSA key ID and package version in mode-0600 config/service.env, without shell export prefixes; systemd’s EnvironmentFile is not a shell script. Put the RSA private PEM and immutable reviewed ZIP in config/. The nginx certificate key is separate from the Go entitlement signing key. Neither is distributed to WordPress. Configure trusted HTTPS origin and public-key map in WordPress.

Review generated files using nginx -t -c /absolute/generated/nginx.conf and systemd-analyze verify /absolute/generated/original-licensing.service on the operator’s target host. Service installation/start, DNS, certificates, firewall, monitoring and paid-provider setup remain external actions. This checkout does not perform them. Linux systemd runtime confinement is not claimed proven by a configuration syntax check; verify actual startup/readiness on the target host.

Follow backup and recovery, customer-operations and key rotation instructions before exposing any restored deployment. Recovery requires trusted latest records; templates cannot establish their freshness.

References: nginx HTTPS, request limits, and systemd execution.