# Edge Configuration

The edge reads all of its configuration from environment variables at startup. Restart it after any change.

## Settings

| Variable | Required | Default | Description |
|---|---|---|---|
| `OCTET_URL` | Yes | A local address | The Octet API. Set it to `https://geo.octetproof.com`. If it is unset, the edge still starts, but every session fails with `502` `octet_unreachable`. |
| `LICENSE` | Yes | Unset | Your license token, `octet_live_v4.public....`. See [Credentials](/docs/browser/integration/credentials/). |
| `ALLOWED_ORIGIN` | Yes | `*` | The origins allowed to call the edge from a browser, comma-separated with no spaces, for example `https://www.example.com,https://app.example.com`. Applies to both the POST and the WebSocket. The default `*` allows any origin, so always set it in production. |
| `PORT` | Yes | `8080` | The TCP port to listen on. Use `443` in production. |
| `EDGE_TLS_CERT_FILE` | Yes | Unset | Path to your TLS certificate chain in PEM format, such as a Let's Encrypt `fullchain.pem`. |
| `EDGE_TLS_KEY_FILE` | Yes | Unset | Path to the matching private key in PEM format, such as `privkey.pem`. |
| `EDGE_DEBUG` | No | Off | `1` or `true` logs one line per request, including the end-user's IP address. Use it only for short diagnostic sessions, and never leave it on in production. |
| `OCTET_CA_FILE` | No | Unset | Mutual TLS to Octet. Path to the CA certificate that Octet's server certificate must chain to. |
| `EDGE_CLIENT_CERT_FILE` | No | Unset | Mutual TLS to Octet. Path to your client certificate. |
| `EDGE_CLIENT_KEY_FILE` | No | Unset | Mutual TLS to Octet. Path to your client certificate's private key. |

The edge serves HTTPS only when both `EDGE_TLS_CERT_FILE` and `EDGE_TLS_KEY_FILE` are set. Without them it serves plain HTTP, which browsers will refuse to use from an HTTPS page. It accepts TLS 1.2 and 1.3, with modern AEAD cipher suites only. It loads the certificate at startup, so restart it after each renewal.

The edge supports mutual TLS to Octet, but Octet doesn't require it today. Set the three mutual TLS variables only if Octet sends you a client certificate.

## Testing only

The edge also reads two settings meant for testing. Leave both unset in production.

| Variable | Effect |
|---|---|
| `EDGE_EXPOSE_VERDICT` | `1` or `true` makes the edge answer the collector's POST with the verdict's `country`, `confidence` and `alarm` instead of `{"ok":true}`. The signed token is never included. |
| `EXIT_IP` | Replaces the user's IP address with this value for every session. It is for local tests where the browser reaches the edge over loopback. |

## Endpoints

| Method | Path | Called by | Response |
|---|---|---|---|
| `GET` | `/health` | You, for monitoring | `200` `{"ok":true,"role":"octet-edge"}`. Does not contact Octet. |
| `POST` | `/v1/signals` | The collector | `200` `{"ok":true}` when Octet accepted the session. Errors are in [Errors](/docs/browser/reference/errors/). |
| `GET` | `/v1/ws` | The collector | A WebSocket upgrade. It stays open for at most 15 seconds. |
| `OPTIONS` | `/v1/signals` | The browser, for CORS | `204` with the CORS headers. |

The edge serves every path at its root, so `apiUrl` is the edge's origin with no path, for example `https://octet.example.com`.

## Ports and connections

| Direction | Protocol and port | Peer |
|---|---|---|
| Inbound | TCP 443 | Browsers, for HTTPS and the WebSocket |
| Outbound | TCP 443 | `geo.octetproof.com` |

The edge must accept the browser's TCP connection directly. See [Deploy the Edge](/docs/browser/integration/deploy-edge/#nothing-may-terminate-tls-or-tcp-in-front-of-the-edge).

## Binaries

The [v1.2.0 release](https://github.com/octetproof/octet-browser/releases/tag/v1.2.0) contains static Linux binaries with no runtime dependencies:

| File | Platform |
|---|---|
| `octet-edge-linux-amd64` | Linux on x86-64 |
| `octet-edge-linux-arm64` | Linux on 64-bit ARM |

Check each binary against the release's `SHA256SUMS` before you install it. See [Deploy the Edge](/docs/browser/integration/deploy-edge/#1-download-and-verify-the-binary). The edge runs only on Linux.
