Go-Live Checklist
Work through the checklist, then run the four tests. The examples use octet.example.com for your edge and www.example.com for your site.
Checklist
Edge
- [ ] The edge runs on its own hostname, with a DNS record pointing straight at the host or at a passthrough layer 4 load balancer. See Deploy the Edge.
- [ ] No proxy, application load balancer or CDN terminates TCP or TLS in front of the edge.
- [ ]
https://octet.example.com/healthreturns{"ok":true,"role":"octet-edge"}. - [ ] The license check below returns
missing_fields. - [ ] The edge binary matches its checksum in the release's
SHA256SUMS. - [ ]
ALLOWED_ORIGINlists exactly the origins that load the collector. - [ ]
EDGE_DEBUG,EDGE_EXPOSE_VERDICTandEXIT_IPare unset. See Edge Configuration. - [ ] Certificate renewal restarts the edge. Check with
sudo certbot renew --dry-run --run-deploy-hooks.
Page
- [ ] You serve
octet-collector.jsv1.2.0 from your own origin with itsintegrityhash, or install the v1.2.0 package tarball from the release. - [ ] Your Content Security Policy allows the hosts for your mode and
worker-src blob:. See Network and CSP. - [ ] Each page view gets a new random
sessionRef, created and stored on your backend. - [ ]
start()runs at page load, andready()runs at the moment of action.
Backend
- [ ] The read token comes from your secret store, never from code.
- [ ] Your HTTP client's timeout is longer than
waitMs. - [ ] Your policy says what happens when the fetch returns
404. - [ ] Your policy acts on
alarmofmediumor above, as well as oncountry. See Verdicts. - [ ] If you store verdicts, you verify and store the
token. See Verify the Signed Token.
Operations
- [ ] Your calendar has reminders before the read token expires and before the license token's 365 days are up.
- [ ] Your privacy notice covers the data in Privacy and Data.
License check
This request proves that your edge can reach Octet and that Octet accepts your license token. It sends an empty body, which Octet refuses only after it has checked the license:
curl -s -X POST https://octet.example.com/v1/signals -H 'content-type: application/json' -d '{}'
With a valid license token, the response is 400:
{"error":"octet_rejected","reason":"missing_fields","status":400}
A 401 with a different reason means the license was refused. See Errors.
Test 1: an honest session
- On a normal connection with no VPN, open a page that runs the collector.
- Trigger the action that calls
ready(). - On your backend, fetch the verdict for that
sessionRef.
Expect: 200, country set to the country you are in, and alarm of none. A low alarm is also normal, for example when your device is set up for another country. Verify the token with the code from Verify the Signed Token and check that it passes.
Test 2: a session through a VPN
- Connect to a commercial VPN that exits in a different country from the one you are in.
- Repeat test 1 in the default
fullmode.
Expect: alarm of medium or high. Octet reports an estimate, so a masked session is not flagged every time. If a VPN session keeps coming back as none, check that nothing terminates TCP or TLS in front of your edge, and that the page is running in full mode.
Test 3: an expired or revoked token
- In the portal's Read tokens tab, mint a 30-day read token, then revoke it.
- Wait a few minutes, then fetch a verdict with it.
Expect: 401 with {"error":"revoked"}. An expired read token gets {"error":"expired"}, and your backend should handle both the same way: alert, and switch to a live token.
To test an expired verdict token, run the expired case from Test the examples. Your verifier must reject it.
Test 4: a rejected license
Run this on a test edge, never on your production edge.
- Set
LICENSE=octet_live_invalidin the edge's environment file and restart the edge. - Run the license check above.
- Load a page that runs the collector against this edge.
Expect: the license check returns 401 with "reason":"malformed_token". In the browser, ready() rejects with signal report failed: 401. Your backend's fetch for that sessionRef returns 404, because no verdict was produced.
Restore the real license token and restart the edge when you are done.