Publisher and central host: 10.0.0.2.
Publisher listener: 10.0.0.2:8443, TLS only.
Central-ingest listener: 10.0.0.2:8444, TLS only.
Required before activation: nexxvu-publisher and nexxvu-central non-login accounts; committed launchd plists validated using /Library/Application Support/NEXXVU/release-plane/venv/bin/python; release-plane database initialized with migrations 001 and 002; immutable publication tree; release public key only; separate publisher and Portal bearer credentials; portal-registry binding for installation c69b370f-41b0-4b89-b793-df059cd58777 and Portal nexxvu-portal-b; TLS certificates with the approved address/name identities; approved listener and firewall rules; authenticated Version Register boundary; external backup destination and successful restore rehearsal.
Neither runtime account may access either signing private key. No plaintext remote bearer-token transport is permitted.
