Edge Configuration
The edge reads all of its configuration from environment variables at startup. Restart it after any change.
Settings
| Variable | Required | Default | Description |
|---|---|---|---|
OCTET_URL |
Yes | A local address | The Octet API. Set it to https://geo.octetproof.com. If it is unset, the edge still starts, but every session fails with 502 octet_unreachable. |
LICENSE |
Yes | Unset | Your license token, octet_live_v4.public.…. See Credentials. |
ALLOWED_ORIGIN |
Yes | * |
The origins allowed to call the edge from a browser, comma-separated with no spaces, for example https://www.example.com,https://app.example.com. Applies to both the POST and the WebSocket. The default * allows any origin, so always set it in production. |
PORT |
Yes | 8080 |
The TCP port to listen on. Use 443 in production. |
EDGE_TLS_CERT_FILE |
Yes | Unset | Path to your TLS certificate chain in PEM format, such as a Let's Encrypt fullchain.pem. |
EDGE_TLS_KEY_FILE |
Yes | Unset | Path to the matching private key in PEM format, such as privkey.pem. |
EDGE_DEBUG |
No | Off | 1 or true logs one line per request, including the end-user's IP address. Use it only for short diagnostic sessions, and never leave it on in production. |
OCTET_CA_FILE |
No | Unset | Mutual TLS to Octet. Path to the CA certificate that Octet's server certificate must chain to. |
EDGE_CLIENT_CERT_FILE |
No | Unset | Mutual TLS to Octet. Path to your client certificate. |
EDGE_CLIENT_KEY_FILE |
No | Unset | Mutual TLS to Octet. Path to your client certificate's private key. |
The edge serves HTTPS only when both EDGE_TLS_CERT_FILE and EDGE_TLS_KEY_FILE are set. Without them it serves plain HTTP, which browsers will refuse to use from an HTTPS page. It accepts TLS 1.2 and 1.3, with modern AEAD cipher suites only. It loads the certificate at startup, so restart it after each renewal.
The edge supports mutual TLS to Octet, but Octet doesn't require it today. Set the three mutual TLS variables only if Octet sends you a client certificate.
Testing only
The edge also reads two settings meant for testing. Leave both unset in production.
| Variable | Effect |
|---|---|
EDGE_EXPOSE_VERDICT |
1 or true makes the edge answer the collector's POST with the verdict's country, confidence and alarm instead of {"ok":true}. The signed token is never included. |
EXIT_IP |
Replaces the user's IP address with this value for every session. It is for local tests where the browser reaches the edge over loopback. |
Endpoints
| Method | Path | Called by | Response |
|---|---|---|---|
GET |
/health |
You, for monitoring | 200 {"ok":true,"role":"octet-edge"}. Does not contact Octet. |
POST |
/v1/signals |
The collector | 200 {"ok":true} when Octet accepted the session. Errors are in Errors. |
GET |
/v1/ws |
The collector | A WebSocket upgrade. It stays open for at most 15 seconds. |
OPTIONS |
/v1/signals |
The browser, for CORS | 204 with the CORS headers. |
The edge serves every path at its root, so apiUrl is the edge's origin with no path, for example https://octet.example.com.
Ports and connections
| Direction | Protocol and port | Peer |
|---|---|---|
| Inbound | TCP 443 | Browsers, for HTTPS and the WebSocket |
| Outbound | TCP 443 | geo.octetproof.com |
The edge must accept the browser's TCP connection directly. See Deploy the Edge.
Binaries
The v1.2.0 release contains static Linux binaries with no runtime dependencies:
| File | Platform |
|---|---|
octet-edge-linux-amd64 |
Linux on x86-64 |
octet-edge-linux-arm64 |
Linux on 64-bit ARM |
Check each binary against the release's SHA256SUMS before you install it. See Deploy the Edge. The edge runs only on Linux.