tollgate-server
The control-plane HTTP service of
Tollgate: fenced lease allocation,
snapshot distribution, idempotent usage ingest, credential issuance, and
account administration, over any tollgate-store backend.
It is latency-tolerant by design. Its contract is correctness (no
double-spend, fencing, idempotent ingest), enforced by the backend it is built
over; anything implementing the Backend seam serves identically.
Surface
Under /v1: lease acquire, release, consolidate and reclaim; revisioned
credential pages; the snapshot catalogue and snapshot fetch; usage ingest; and
account, key, and snapshot administration. /livez and /readyz are the
probes.
Every protected handler requires verified instance, operator or provisioner evidence, with disjoint roles; a provisioner reaches only the self-service subset of the admin API, on accounts a provisioner created. The server owns TLS and refuses exposed plaintext; mutual TLS, rotating bearer credentials, and Google service identity are supported, and rotate without a restart. Administrative actions emit audit events carrying receipts the backend captured at mutation.
Running it
The tollgate-server binary reads:
TOLLGATE_SECURITY_CONFIG: the required JSON security manifest (identities, TLS, and optionally an issuer secret).TOLLGATE_BIND: the listen address, default127.0.0.1:8080.TOLLGATE_STORE:memory(the default; ephemeral, for development) orpostgres.TOLLGATE_PG_URL: the PostgreSQL connection URL, for thepostgresstore.TOLLGATE_RECLAIM_INTERVAL_SECS: the expiry sweep interval, default 5.
docs/CONTROL_PLANE_SECURITY.md
covers deployment, credential rotation, and audit collection;
docs/ACCOUNT_ADMINISTRATION.md
covers operator actions.
Features
postgres(default): the PostgreSQL backend, viatollgate-store-postgres. Without it, the server builds with no database dependency.test-support: test-only APIs of the PostgreSQL backend (destructive fixture reset, query-plan inspection). Not for production builds, and not covered by semantic versioning: it may change in any release.
Contract
INVARIANTS.md
specifies the ledger, fencing, and ingest rules the server enforces through its
backend.
License
MIT OR Apache-2.0, at your option. Tollgate is a product of MorphIQ Labs, a trade name of Prophetizo LLC.