3.8 KiB
DC AMD Connector
DC AMD Connector runs on the adjacent AMD Windows machine. It is a restricted
HTTP CONNECT proxy for the NODE.DC map path:
NAS DC AMD Proxy -> 172.22.0.183:8791 -> AMD VPN -> Cesium / Bing
It is not a general-purpose proxy:
- only authenticated
CONNECTrequests are accepted; - only port
443is accepted; - only Cesium Ion and required Bing imagery hosts are accepted;
- ordinary HTTP proxy requests are rejected;
- the Ion bearer token stays inside the end-to-end TLS connection from NAS to Cesium and is not processed or logged by this connector.
The Windows host owns the VPN. The NAS uses only the stable LAN address in
.env, never an OpenVPN adapter address or a changing public VPN exit IP.
First run on the AMD machine
-
Start Docker Desktop and wait for its engine to be running.
-
Open PowerShell as Administrator and run
install.ps1from this package folder. It verifies source checksums, copies the package toC:\\NODEDC\\dc-amd-connector, creates a local random access token without printing it, binds port8791only to172.22.0.183, scopes Windows Firewall to NAS172.22.0.222, constrains the container to one CPU, 256 MB, 64 processes and 4096 file descriptors, and starts the container. It also adds a launcher to the current user's Windows Startup folder. At the next user sign-in it uses the Docker Desktop CLI when available, otherwise its installed application; theunless-stoppedrestart policy then restores this container.powershell -NoProfile -ExecutionPolicy Bypass -File .\\install.ps1 -
Do not send the runtime secret in chat or put it into a source file. The next NAS patch will provision the same value in a root-owned secret file through an operator-only transfer.
Docker Desktop on the WSL 2 backend is a desktop application, not an unattended Windows boot daemon. Thus this recovery guarantee starts after the configured Windows user signs in. Before a sign-in, the map must use its offline/tile-cache path. No Windows route, VPN, DNS, proxy setting or other application's traffic is modified.
Operations and migration
Run these commands from an elevated PowerShell window:
cd C:\\NODEDC\\dc-amd-connector
docker compose ps
docker compose logs --tail 100
docker compose restart
docker compose down is an intentional stop and removes the container; restore
it with docker compose up -d. The auto-start launcher is removed by
uninstall.ps1.
To move to a different adjacent Windows host: install this same package there
with its stable LAN address (-BindAddress) and verify its VPN tunnel first.
It creates a fresh local access secret. Only then may the separate NAS pairing
patch be changed to the new host; never run two active pairings against the
same NAS endpoint.
Verification
The connector health check uses the local runtime secret inside the container.
It is expected to become healthy without making any external request. The
following local check proves a permitted TLS tunnel through the current AMD VPN
without revealing the access token:
docker exec dc-amd-connector node -e "const fs=require('fs'),net=require('net');const t=fs.readFileSync('/run/dc-amd-secrets/connector-access','utf8').trim();const s=net.connect(8791,'127.0.0.1',()=>s.write('CONNECT api.cesium.com:443 HTTP/1.1\r\nHost: api.cesium.com:443\r\nProxy-Authorization: Bearer '+t+'\r\n\r\n'));s.once('data',d=>{const v=d.toString('ascii');console.log(v.split('\r\n')[0]);s.destroy();process.exit(v.startsWith('HTTP/1.1 200')?0:1)});s.on('error',e=>{console.error(e.message);process.exit(1)})"
Expected output is HTTP/1.1 200 Connection Established. If the AMD VPN is
off, this test must fail; it must never silently move live Cesium traffic to
the NAS.