README: obfuscation layer docs
This commit is contained in:
14
README.md
14
README.md
@@ -66,3 +66,17 @@ schtasks /create /tn PostalWatchdog /tr "C:\Mailer\watchdog.bat" /sc minute /mo
|
||||
| start.bat | launcher (opens browser, runs app) |
|
||||
| watchdog.bat | health-check + auto-restart |
|
||||
| ollama_shim.py | deploys to nightmare — non-chunked Ollama proxy on tailnet |
|
||||
|
||||
|
||||
## Obfuscation layer (v1.2)
|
||||
|
||||
- **ollama-shim v2** (nightmare): binds tailnet-only `100.103.34.0:28443` — nonstandard port,
|
||||
token-gated (`X-Auth-Token`, constant-time compare), paths `/tags` + `/gen` (nothing fingerprints
|
||||
as Ollama), replies carry a fake `nginx` server header, generic 404 on everything else.
|
||||
- **Postal remote dashboard**: second Flask listener on the VPS tailnet IP only
|
||||
(`100.120.108.13:47077`), token-gated via `?t=<operator_token>` or `X-Auth-Token` header —
|
||||
open Postal from any tailnet device without RDP. Localhost :8899 stays token-free for RDP use.
|
||||
- Secrets live in `C:\Mailer\shared_secret.txt` (shim) and `C:\Mailer\operator_token.txt`
|
||||
(dashboard gate); shim copy at `/opt/ollama-shim/shared_secret.txt` on nightmare.
|
||||
- Wire-level encryption is WireGuard (Tailscale) end-to-end; this layer hides *what* the services
|
||||
are and who may talk to them.
|
||||
|
||||
Reference in New Issue
Block a user