# T12 · frp server (frps) — v0.8 MVP transport stepping-stone. # # Single-node frps on the VPS with WILDCARD vhost so `*.term.` routes by subdomain to # each agent's proxy (EXPLORE §5.4). Contract-compatible with the native §4.1 mux so the v0.9 swap # reshapes nothing (frp subdomain vhost → T7 router; frp login plugin → T8 gate; yamux → §4.1 mux). # # TLS: terminate here OR at Cloudflare in front (M6 scheme-following preserved end-to-end). Values # below reference environment via your process manager; DO NOT commit real secrets (INV5/INV9). bindPort = 7000 # agent (frpc) control connection # Wildcard subdomain vhost — the tenant routing substrate. vhostHTTPSPort = 443 # browser-facing wss:// (or set vhostHTTPPort behind Cloudflare TLS) subdomainHost = "term.example.com" # = BASE_DOMAIN; *.term.example.com routes by leftmost label # Deny-by-default auth at the edge (the auth the base app never had, EXPLORE §5.5). # The server-plugin delegates EVERY Login/NewProxy/NewUserConn decision to P3's control plane # via plugin-hook.ts — no tenancy logic lives in frps (v0.8 shared-token gate is a KNOWN, # temporary shortcut, replaced by capability tokens + mTLS in v0.9). [[httpPlugins]] name = "control-plane-authz" addr = "127.0.0.1:9001" # plugin-hook.ts HTTP shim → P3 authz endpoint path = "/handler" ops = ["Login", "NewProxy", "NewUserConn"] # Opaque forwarding only — frps forwards TCP/WS streams and parses NO terminal bytes (INV11).