README: obfuscation layer docs

This commit is contained in:
Hermes
2026-10-02 02:21:52 -07:00
parent 1e3aaf3193
commit a7b53ac6c0

View File

@@ -66,3 +66,17 @@ schtasks /create /tn PostalWatchdog /tr "C:\Mailer\watchdog.bat" /sc minute /mo
| start.bat | launcher (opens browser, runs app) |
| watchdog.bat | health-check + auto-restart |
| ollama_shim.py | deploys to nightmare — non-chunked Ollama proxy on tailnet |
## Obfuscation layer (v1.2)
- **ollama-shim v2** (nightmare): binds tailnet-only `100.103.34.0:28443` — nonstandard port,
token-gated (`X-Auth-Token`, constant-time compare), paths `/tags` + `/gen` (nothing fingerprints
as Ollama), replies carry a fake `nginx` server header, generic 404 on everything else.
- **Postal remote dashboard**: second Flask listener on the VPS tailnet IP only
(`100.120.108.13:47077`), token-gated via `?t=<operator_token>` or `X-Auth-Token` header —
open Postal from any tailnet device without RDP. Localhost :8899 stays token-free for RDP use.
- Secrets live in `C:\Mailer\shared_secret.txt` (shim) and `C:\Mailer\operator_token.txt`
(dashboard gate); shim copy at `/opt/ollama-shim/shared_secret.txt` on nightmare.
- Wire-level encryption is WireGuard (Tailscale) end-to-end; this layer hides *what* the services
are and who may talk to them.