MAQPNADocs

maqpna license issue

Sign and print a licence (for licence issuers)

Operate-o json | yaml

Synopsis#

maqpna license issue --key KEYURI --id ID --customer C --edition enterprise|sovereign|operator
                     (--days N | --not-after RFC3339) [--feature F]... [--nodes N] [--tenants N] [--sandbox-hours N]

Description#

From the help of maqpna license:

install creates or updates the licence Secret (Helm license.secretRef; default: the Secret the gateway/operator mount, else maqpna-license, key license) in the install namespace. The gateway and operator re-read it within about a minute (kubelet Secret sync + 30 s poll), no restart. status reads that Secret, evaluates it with this binary's keys and shows this month's billable nodes against the licence's node limit.

verify checks a licence against the keys built into this binary (or --pubkey, a PEM of Ed25519 or EC P-256 public keys, for checking a licence before it ships; a licence that only verifies with --pubkey enables nothing in a real install). issue signs a licence with a key URI and prints it: an Ed25519 key (a PKCS#8 file, pkcs11: or kms:) signs EdDSA, an Azure Key Vault EC P-256 key (azurekv://VAULT/KEY[/VERSION]) signs ES256. Azure credentials come from AZURE_TENANT_ID, AZURE_CLIENT_ID and AZURE_CLIENT_SECRET, else AZURE_FEDERATED_TOKEN_FILE (workload identity), else the az CLI login.

A licence only switches commercial features on; no licence state ever blocks agent traffic (docs/business/implementation-plan.md P0-4).

Flags#

FlagTypeDescriptionDefault
--customerstringcustomer id (sub)none
--daysintvalidity in days from nownone
--editionstringenterprise | sovereign | operatornone
--featurestringenabled feature (repeatable; * = all)none
--idstringlicence id (jti)none
--keystringsigning key: a PKCS#8 PEM file or azurekv://VAULT/KEY[/VERSION] (pkcs11: and kms:// need a custom build with a backend)none
--nodesintnode limit (0 = unlimited)none
--not-afterstringexpiry (RFC 3339); alternative to --daysnone
--sandbox-hoursintsandbox-hours per month (0 = unlimited)none
--tenantsinttenant limit (0 = unlimited)none

The global flags (--context, -o, --no-color, ...) work with every command.

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna license issue.cast