maqpna license issue
Sign and print a licence (for licence issuers)
Synopsis#
maqpna license issue --key KEYURI --id ID --customer C --edition enterprise|sovereign|operator
(--days N | --not-after RFC3339) [--feature F]... [--nodes N] [--tenants N] [--sandbox-hours N]Description#
From the help of maqpna license:
install creates or updates the licence Secret (Helm license.secretRef; default: the Secret the gateway/operator mount, else maqpna-license, key license) in the install namespace. The gateway and operator re-read it within about a minute (kubelet Secret sync + 30 s poll), no restart. status reads that Secret, evaluates it with this binary's keys and shows this month's billable nodes against the licence's node limit.
verify checks a licence against the keys built into this binary (or --pubkey, a PEM of Ed25519 or EC P-256 public keys, for checking a licence before it ships; a licence that only verifies with --pubkey enables nothing in a real install). issue signs a licence with a key URI and prints it: an Ed25519 key (a PKCS#8 file, pkcs11: or kms:) signs EdDSA, an Azure Key Vault EC P-256 key (azurekv://VAULT/KEY[/VERSION]) signs ES256. Azure credentials come from AZURE_TENANT_ID, AZURE_CLIENT_ID and AZURE_CLIENT_SECRET, else AZURE_FEDERATED_TOKEN_FILE (workload identity), else the az CLI login.
A licence only switches commercial features on; no licence state ever blocks agent traffic (docs/business/implementation-plan.md P0-4).
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--customer | string | customer id (sub) | none |
--days | int | validity in days from now | none |
--edition | string | enterprise | sovereign | operator | none |
--feature | string | enabled feature (repeatable; * = all) | none |
--id | string | licence id (jti) | none |
--key | string | signing key: a PKCS#8 PEM file or azurekv://VAULT/KEY[/VERSION] (pkcs11: and kms:// need a custom build with a backend) | none |
--nodes | int | node limit (0 = unlimited) | none |
--not-after | string | expiry (RFC 3339); alternative to --days | none |
--sandbox-hours | int | sandbox-hours per month (0 = unlimited) | none |
--tenants | int | tenant limit (0 = unlimited) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
What happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |