pub struct NodeServerConfig {
pub endpoint: String,
pub node_id: NodeId,
pub workspaces: Vec<WorkspaceConfig>,
pub runtime: NativeRuntimeConfig,
/* private fields */
}Fields§
§endpoint: String§node_id: NodeId§workspaces: Vec<WorkspaceConfig>§runtime: NativeRuntimeConfigImplementations§
Source§impl NodeServerConfig
impl NodeServerConfig
pub fn new( endpoint: impl Into<String>, access_token: impl Into<String>, node_id: NodeId, workspaces: impl IntoIterator<Item = WorkspaceConfig>, ) -> Result<Self, NodeServerError>
pub fn with_api_listen( self, api_listen: SocketAddr, ) -> Result<Self, NodeServerError>
Sourcepub fn with_bridge_listen(
self,
bridge_listen: SocketAddr,
) -> Result<Self, NodeServerError>
pub fn with_bridge_listen( self, bridge_listen: SocketAddr, ) -> Result<Self, NodeServerError>
Opt-in node-envelope HTTP+WS bridge listener. Loopback only (same spirit
as with_api_listen). Does not enable by default — libraries and the
binary leave this None until --bridge-listen / with_bridge_listen.
Sourcepub fn with_bridge_token(
self,
bridge_token: impl Into<String>,
) -> Result<Self, NodeServerError>
pub fn with_bridge_token( self, bridge_token: impl Into<String>, ) -> Result<Self, NodeServerError>
Optional bridge shared secret, distinct from the C2/node access token. Never log the value. Empty / oversize refused.
Sourcepub fn with_bridge_underlay(
self,
bind: SocketAddr,
transport_key: [u8; 32],
underlay_token: impl Into<String>,
) -> Result<Self, NodeServerError>
pub fn with_bridge_underlay( self, bind: SocketAddr, transport_key: [u8; 32], underlay_token: impl Into<String>, ) -> Result<Self, NodeServerError>
Tip 6: point bridge reachability over mesh underlay (UDP+AEAD relay to
local loopback --bridge-listen). Requires bridge listen + bridge token
already configured. Transport key is 32 raw bytes (never logged).
Underlay auth token is distinct from BRIDGE_TOKEN (crypto ≠ auth).
Sourcepub fn with_call_home(self, relay: SocketAddr) -> Result<Self, NodeServerError>
pub fn with_call_home(self, relay: SocketAddr) -> Result<Self, NodeServerError>
Also dial relay and serve this wire over the connection, in
addition to accepting on the local endpoint.
Who opens the socket and who is the protocol’s server are separate
questions, and this is the node’s half of separating them. The node
stays the server either way – it answers NodeRequests and emits
NodeEvents exactly as it does for a relay that dialled it. All
that changes is that a node with no address anyone can reach makes
the connection itself, and names itself once it arrives (see
gate4agent_node_wire::write_call_home_announce).
Loopback only, and that is not an oversight to be flagged and worked around. This wire carries terminal contents, keystrokes and file bytes as plaintext JSON; its mutual challenge-response authenticates both ends and encrypts nothing. Every listener in this stack is loopback-guarded for that reason, and a dialler must hold the same line – a node calling a public relay would put the whole control plane on the wire in the clear. Reaching a relay on another host is a transport question, and it stays unanswered here on purpose: this change is about direction, not distance.
pub fn with_state_path( self, state_path: impl Into<PathBuf>, ) -> Result<Self, NodeServerError>
pub fn with_spawn_profiles(self, spawn_profiles: SpawnProfileRegistry) -> Self
Sourcepub fn with_session_record_retention(
self,
retention: SessionRecordRetentionConfig,
) -> Self
pub fn with_session_record_retention( self, retention: SessionRecordRetentionConfig, ) -> Self
Sets the age/keep-N policy the drive loop’s retention sweep uses to
retire dead ManagedSessionState::Unavailable records. Both fields
default to 0 (disabled) via SessionRecordRetentionConfig::default
when this is never called – a node never deletes a durable record
until an operator opts in with a real value.
pub fn with_session_environment_materialization( self, root: impl Into<PathBuf>, resolver: Arc<dyn NodeSecretResolver>, ) -> Result<Self, NodeServerError>
Sourcepub fn with_history(self, history: NativeHistoryConfig) -> Self
pub fn with_history(self, history: NativeHistoryConfig) -> Self
Enables bounded provider-history discovery and loading from explicit host-owned roots. Ambient vendor homes are never inferred here.
Sourcepub fn with_harness_mcp_helper(
self,
helper_program: impl Into<PathBuf>,
) -> Result<Self, NodeServerError>
pub fn with_harness_mcp_helper( self, helper_program: impl Into<PathBuf>, ) -> Result<Self, NodeServerError>
Enables the H3B read proxy with one exact operator-reviewed helper file.
Linux/macOS use owner-only UDS; Windows uses owner-only named pipes.
Both platforms review the helper the same way (absolute regular file +
identity hash) — the old cfg(not(windows)) hard-refuse was a leftover
gate after Unix listener/peer-cred support landed.
Sourcepub fn with_network_allowlist_catalog(
self,
catalog: NetworkAllowlistCatalog,
) -> Result<Self, NodeServerError>
pub fn with_network_allowlist_catalog( self, catalog: NetworkAllowlistCatalog, ) -> Result<Self, NodeServerError>
Install an in-memory station network allowlist catalog (opaque ids + optional node-local permits / provider-native mapping). Empty remains the default — unknown spawn ids refuse at resolve. Never cookies / OAuth / proxy credentials. C2 / inventory still list ids only.
Sourcepub fn with_network_allowlist_catalog_file(
self,
path: impl AsRef<Path>,
) -> Result<Self, NodeServerError>
pub fn with_network_allowlist_catalog_file( self, path: impl AsRef<Path>, ) -> Result<Self, NodeServerError>
Load station network allowlist catalog from an absolute regular file
(v1 id-list or v2 JSON schema). Unset path is not used here — callers
that want env fallback use resolve_network_allowlist_catalog.