Local license sidecar — UDP-facing cache between products and licenses.datatailr.com
570
Local license sidecar for Datatailr products (QE, Wire, Tick, …).
Pure C, single binary, runs one per customer site. Pulls signed
license blobs from the central datatailr/license-server
over HTTPS, caches them, and serves them to product daemons over
UDP. Holds a 72-hour grace cache so customers stay operational
through transient central-server outages.
This is the edge half of the licensing stack. Customers don't talk
to the central license server directly — every Datatailr daemon
(QE, wire-controller, wire-meshd, tick-server, …) is built against
libdtlicense.so which talks to this sidecar on UDP.
docker run -d --name dt-license-edge \
--network host \
-e DT_LICENSE_CENTRAL=https://licenses.datatailr.com \
-e DT_LICENSE_API_KEY=<edge-role-API-key-from-central> \
-e DT_LICENSE_PORT=3333 \
-v /var/lib/dt-license-edge:/var/lib/dt-license-edge \
--restart unless-stopped \
datatailr/license-edge:latest
The DT_LICENSE_API_KEY is one of your Datatailr-issued API keys with
the edge role — create it via the central server's web UI (API Keys
→ Create → Role: edge). Same key for all sites, or one per site if you
want per-site audit visibility.
Product daemons on the same network are then started with:
dt-query-engine ... --local-license-server <edge-host>:3333
# or
wire-meshd ... --local-license-server <edge-host>:3333
# or via env:
DT_LICENSE_LOCAL_SERVER=<edge-host>:3333 wire-kmsd ...
The first time a daemon fetches, the edge contacts central, gets back a signed license bound to that daemon's host UUID, and caches it. Subsequent fetches from the same host are served from cache. The edge re-refreshes from central every 10 minutes by default.
| Variable / Flag | Default | What it does |
|---|---|---|
DT_LICENSE_CENTRAL / --central | https://licenses.datatailr.com | URL of the central license server. |
DT_LICENSE_API_KEY / --api-key | required | API key with edge role, sent as X-Api-Key to central. |
DT_LICENSE_PORT / --port | 3333 | UDP listen port for product daemons. |
DT_LICENSE_CACHE / --cache | /var/lib/dt-license-edge/cache.json | Persisted cache (license blob + last refresh time per host). |
Run it on a stable internal IP — daemons reference it by host:port.
A single edge can serve hundreds of product daemons on a network.
When the central server is unreachable, the edge keeps serving cached
licenses for 72 hours by default. After that it returns DENY and
daemons fail their next license check. The grace window is per-host —
once central comes back, refreshes resume and the timer resets.
A 410 Gone response from central immediately drops the cached
license from the edge (revocation flow), regardless of grace remaining.
proto/dt_license_proto.h in the repodatatailr/license-serverlibdtlicense.so — linked by every product binaryProprietary — LicenseRef-Datatailr-Proprietary.
Content type
Image
Digest
sha256:a8f1351f1…
Size
5.8 MB
Last updated
4 months ago
docker pull datatailr/license-edge