404PrivacyDocs

Control plane and CA

STATIC has two local listeners in proxy mode: one for browser traffic and a second for management. The control port defaults to the proxy listener port plus two: 4042 with the sample 4040 config, or 8445 with the no-config CLI listener at 8443.

One active profile

At startup, app.rs creates a ProfileStore and gives clones of that shared in-memory store to both the request pipeline and control plane. Proxy mode refuses to start without an explicit CLI or configured default profile. Selecting another profile changes what new Flows pick up; a Flow already in progress holds its selected metadata. On Linux, selection also attempts a sync to the pinned packet map where configured.

Local endpoints

Method and routePurpose
GET /statusMode and readiness.
GET /ca/status, POST /ca/initPublic CA certificate status and initialization.
GET /profiles/catalog, GET /profiles/activeCatalog metadata and active selection.
POST /profiles/select, POST /profiles/validateSelect a profile; return coherence warnings for a submitted profile.
GET /telemetry/snapshotRecent in-process events.
POST /stopRequest shutdown.

If control.token_path is configured with a nonempty token, every endpoint checks X-404-Control-Token. The packaged Windows path uses a token. With no configured token, the code imposes no token check: keep the control bind address on loopback and do not expose that listener to a network. This API is for local supervision; an API section can later carry endpoint examples and a stable external contract.

Certificate custody and observations

The certificate provider loads or generates the local CA and issues cached leaf certificates per hostname during browser-facing TLS handshakes. /ca/status returns the public PEM, not the private key. The host installer or operator decides whether to trust it. A browser that has not trusted it will report certificate errors on intercepted HTTPS traffic.

Telemetry is written to stdout or JSON mode and retained in a bounded in-process buffer for snapshots. The buffer is not a persistent audit log. Consult control.rs, app.rs, cert.rs, and telemetry.rs.