What it doesBasics
VaaS Server is a relay you run yourself. Two applications that cannot reach each other both connect out to it with credentials of the same tenant and the same fresh token; the relay pairs them and carries their messages both ways. What the messages mean, and their end-to-end encryption, stays with the applications.
How two applications meet at the relay
First applicationConnects out with its credential and the token.
VaaS ServerPairs the two connections and carries messages.
Second applicationSame tenant, same token, its own credential.
- Pair two credential-authenticated peers of one tenant by a shared session token
- Carry opaque messages in both directions over WebSocket
- List and drop tracked sessions through an HTTPS API, per tenant or across tenants
- Container-mesh control plane: membership leases, addresses, hub election and names
First useBasics
- Prepare a server certificate bundle, the credentials-service setting from your on-premise setup and a data volume.
- Start the relay as a container or with its Helm chart, passing TLS through to it.
- Check
GET /health, then an authenticated session list. - Pair two compatible applications with a fresh token and exchange a message each way.
CommandsAdvanced
$ vaas-server serve
$ vaas-server version
$ vaas-server openapi --prefix /vaas
Good to knowHelp
- Run one instance per relay: sessions stay in one process and end on restart or upgrade.
- Applications must authenticate each other and encrypt their payloads end to end.
- A dropped session is a cancellation request; confirm both peers have stopped.