Docs/Octet Browser/Reference/Edge Configuration

Edge Configuration

The edge reads all of its configuration from environment variables at startup. Restart it after any change.

Settings

Variable Required Default Description
OCTET_URL Yes A local address The Octet API. Set it to https://geo.octetproof.com. If it is unset, the edge still starts, but every session fails with 502 octet_unreachable.
LICENSE Yes Unset Your license token, octet_live_v4.public.…. See Credentials.
ALLOWED_ORIGIN Yes * The origins allowed to call the edge from a browser, comma-separated with no spaces, for example https://www.example.com,https://app.example.com. Applies to both the POST and the WebSocket. The default * allows any origin, so always set it in production.
PORT Yes 8080 The TCP port to listen on. Use 443 in production.
EDGE_TLS_CERT_FILE Yes Unset Path to your TLS certificate chain in PEM format, such as a Let's Encrypt fullchain.pem.
EDGE_TLS_KEY_FILE Yes Unset Path to the matching private key in PEM format, such as privkey.pem.
EDGE_DEBUG No Off 1 or true logs one line per request, including the end-user's IP address. Use it only for short diagnostic sessions, and never leave it on in production.
OCTET_CA_FILE No Unset Mutual TLS to Octet. Path to the CA certificate that Octet's server certificate must chain to.
EDGE_CLIENT_CERT_FILE No Unset Mutual TLS to Octet. Path to your client certificate.
EDGE_CLIENT_KEY_FILE No Unset Mutual TLS to Octet. Path to your client certificate's private key.

The edge serves HTTPS only when both EDGE_TLS_CERT_FILE and EDGE_TLS_KEY_FILE are set. Without them it serves plain HTTP, which browsers will refuse to use from an HTTPS page. It accepts TLS 1.2 and 1.3, with modern AEAD cipher suites only. It loads the certificate at startup, so restart it after each renewal.

The edge supports mutual TLS to Octet, but Octet doesn't require it today. Set the three mutual TLS variables only if Octet sends you a client certificate.

Testing only

The edge also reads two settings meant for testing. Leave both unset in production.

Variable Effect
EDGE_EXPOSE_VERDICT 1 or true makes the edge answer the collector's POST with the verdict's country, confidence and alarm instead of {"ok":true}. The signed token is never included.
EXIT_IP Replaces the user's IP address with this value for every session. It is for local tests where the browser reaches the edge over loopback.

Endpoints

Method Path Called by Response
GET /health You, for monitoring 200 {"ok":true,"role":"octet-edge"}. Does not contact Octet.
POST /v1/signals The collector 200 {"ok":true} when Octet accepted the session. Errors are in Errors.
GET /v1/ws The collector A WebSocket upgrade. It stays open for at most 15 seconds.
OPTIONS /v1/signals The browser, for CORS 204 with the CORS headers.

The edge serves every path at its root, so apiUrl is the edge's origin with no path, for example https://octet.example.com.

Ports and connections

Direction Protocol and port Peer
Inbound TCP 443 Browsers, for HTTPS and the WebSocket
Outbound TCP 443 geo.octetproof.com

The edge must accept the browser's TCP connection directly. See Deploy the Edge.

Binaries

The v1.2.0 release contains static Linux binaries with no runtime dependencies:

File Platform
octet-edge-linux-amd64 Linux on x86-64
octet-edge-linux-arm64 Linux on 64-bit ARM

Check each binary against the release's SHA256SUMS before you install it. See Deploy the Edge. The edge runs only on Linux.