# Deployment notes (ptt-server, DNI) This document complements `server/PTT-SERVER.md` with operator-facing deployment items for Device Numeric Identity (DNI) and decentralized routing. ## Environment Set at least the PKI and TLS variables from `CLAUDE.md` (ptt-server section). For group DNS metadata and broadcast gating, also set: | Variable | Purpose | |---|---| | `PTT_DNS_DOMAIN` | If set, eligible talkgroups resolve `tg-.` TXT records (`label`, `type`, etc.). | | `PTT_BROADCAST_AUTH_PATH` | Optional path to JSON allow-list; default is `broadcast-auth.json` in the server working directory. | | `PTT_UST_HMAC_SECRET` | **Required for UDP relay.** 64-hex-char (32-byte) HMAC key used to sign and verify UDP Session Tokens. Without this, `udp_session_token` events are issued with invalid tokens and the UDP path silently fails. Generate with `openssl rand -hex 32`. In multi-node deployments, every node must share the same value. | | `PTT_UDP_PORT` | **Required for UDP relay.** UDP relay port (must also be published via `-p :/udp` in the Docker `create`/`run` command or equivalent compose entry). | | `PTT_UDP_SKE_DISABLED` | Set to `1` to disable UDP Session-Key Envelope (plaintext UDP for debugging or migration). When set, `udp_session_token` omits `skeKey` / `udpRouteId`. Default: unset (SKE enabled). | | `PTT_UDP_SKE_REQUIRE` | Set to `1` to drop inbound UDP that is not SKE-wrapped (`PTTU`). Use only after all clients send SKE. Default: unset (accepts plaintext when SKE is not used). | ## Files on disk - **`broadcast-auth.json`** (optional): Restricts who may transmit on **broadcast**-typed groups (tier 0 defaults, etc.). Keys are string group ids; values are arrays of 16-digit DNIs. **If a group id is omitted from the file, broadcast TX on that group is allowed** (no restriction). If a group id is present with an empty array `[]`, no DNIs may transmit on that group until you add them. If present with DNIs, only those DNIs may transmit. Send **`SIGHUP`** to reload without restart. ## Socket.IO client requirements - Connect with query parameters **`dni`** and **`publicKey`** (base64 SPKI DER). - Complete **`authenticate`** with the same DNI and key proof, then handle **`register_ok`** and join groups with **`group_join`**. ## Redis Redis is **not** required for real-time voice, text, or device routing in DNI mode. You may omit Redis unless other integration uses it.