maqpna license
Install, show, verify or issue MAQPNA licences (offline EdDSA or ES256 JWS)
Synopsis#
maqpna license install FILE|- [-n NS] [--secret NAME] [--key KEY] [--kube-context C]
maqpna license status [-n NS] [--secret NAME] [--key KEY] [--kube-context C] (exit 3 when invalid or expired)
maqpna license verify FILE|- [--pubkey PEM] (exit 3 when invalid or expired)
maqpna license issue --key KEYURI --id ID --customer C --edition enterprise|sovereign|operator
(--days N | --not-after RFC3339) [--feature F]... [--nodes N] [--tenants N] [--sandbox-hours N]Description#
install creates or updates the licence Secret (Helm license.secretRef; default: the Secret the gateway/operator mount, else maqpna-license, key license) in the install namespace. The gateway and operator re-read it within about a minute (kubelet Secret sync + 30 s poll), no restart. status reads that Secret, evaluates it with this binary's keys and shows this month's billable nodes against the licence's node limit.
verify checks a licence against the keys built into this binary (or --pubkey, a PEM of Ed25519 or EC P-256 public keys, for checking a licence before it ships; a licence that only verifies with --pubkey enables nothing in a real install). issue signs a licence with a key URI and prints it: an Ed25519 key (a PKCS#8 file, pkcs11: or kms:) signs EdDSA, an Azure Key Vault EC P-256 key (azurekv://VAULT/KEY[/VERSION]) signs ES256. Azure credentials come from AZURE_TENANT_ID, AZURE_CLIENT_ID and AZURE_CLIENT_SECRET, else AZURE_FEDERATED_TOKEN_FILE (workload identity), else the az CLI login.
A licence only switches commercial features on; no licence state ever blocks agent traffic (docs/business/implementation-plan.md P0-4).
Subcommands#
maqpna license installInstall or update the licence Secret in the cluster
maqpna license statusShow the installed licence and this month's billable nodes
maqpna license verifyVerify a licence file against the keys built into the CLI
maqpna license issueSign and print a licence (for licence issuers)
Examples#
maqpna license install licence.jws
maqpna license status
maqpna license verify licence.jwsWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |