From a7b53ac6c021d933f870830e5f28d6400f1a157c Mon Sep 17 00:00:00 2001 From: Hermes Date: Fri, 2 Oct 2026 02:21:52 -0700 Subject: [PATCH] README: obfuscation layer docs --- README.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/README.md b/README.md index 21b8fbf..872563e 100644 --- a/README.md +++ b/README.md @@ -66,3 +66,17 @@ schtasks /create /tn PostalWatchdog /tr "C:\Mailer\watchdog.bat" /sc minute /mo | start.bat | launcher (opens browser, runs app) | | watchdog.bat | health-check + auto-restart | | ollama_shim.py | deploys to nightmare — non-chunked Ollama proxy on tailnet | + + +## Obfuscation layer (v1.2) + +- **ollama-shim v2** (nightmare): binds tailnet-only `100.103.34.0:28443` — nonstandard port, + token-gated (`X-Auth-Token`, constant-time compare), paths `/tags` + `/gen` (nothing fingerprints + as Ollama), replies carry a fake `nginx` server header, generic 404 on everything else. +- **Postal remote dashboard**: second Flask listener on the VPS tailnet IP only + (`100.120.108.13:47077`), token-gated via `?t=` or `X-Auth-Token` header — + open Postal from any tailnet device without RDP. Localhost :8899 stays token-free for RDP use. +- Secrets live in `C:\Mailer\shared_secret.txt` (shim) and `C:\Mailer\operator_token.txt` + (dashboard gate); shim copy at `/opt/ollama-shim/shared_secret.txt` on nightmare. +- Wire-level encryption is WireGuard (Tailscale) end-to-end; this layer hides *what* the services + are and who may talk to them.