Control plane and CA
STATIC has two local listeners in proxy mode: one for browser traffic and a second for management. The control port defaults to the proxy listener port plus two: 4042 with the sample 4040 config, or 8445 with the no-config CLI listener at 8443.
One active profile
At startup, app.rs creates a ProfileStore and gives clones of that shared in-memory store to both the request pipeline and control plane. Proxy mode refuses to start without an explicit CLI or configured default profile. Selecting another profile changes what new Flows pick up; a Flow already in progress holds its selected metadata. On Linux, selection also attempts a sync to the pinned packet map where configured.
Local endpoints
| Method and route | Purpose |
|---|---|
GET /status | Mode and readiness. |
GET /ca/status, POST /ca/init | Public CA certificate status and initialization. |
GET /profiles/catalog, GET /profiles/active | Catalog metadata and active selection. |
POST /profiles/select, POST /profiles/validate | Select a profile; return coherence warnings for a submitted profile. |
GET /telemetry/snapshot | Recent in-process events. |
POST /stop | Request shutdown. |
If control.token_path is configured with a nonempty token, every endpoint checks X-404-Control-Token. The packaged Windows path uses a token. With no configured token, the code imposes no token check: keep the control bind address on loopback and do not expose that listener to a network. This API is for local supervision; an API section can later carry endpoint examples and a stable external contract.
Certificate custody and observations
The certificate provider loads or generates the local CA and issues cached leaf certificates per hostname during browser-facing TLS handshakes. /ca/status returns the public PEM, not the private key. The host installer or operator decides whether to trust it. A browser that has not trusted it will report certificate errors on intercepted HTTPS traffic.
Telemetry is written to stdout or JSON mode and retained in a bounded in-process buffer for snapshots. The buffer is not a persistent audit log. Consult control.rs, app.rs, cert.rs, and telemetry.rs.