feat: implement Milestone 1 - Proxy Foundation for sandbox credential injection#6
Open
andyjmorgan wants to merge 1 commit intomainfrom
Open
feat: implement Milestone 1 - Proxy Foundation for sandbox credential injection#6andyjmorgan wants to merge 1 commit intomainfrom
andyjmorgan wants to merge 1 commit intomainfrom
Conversation
845ce66 to
7f2e8cb
Compare
… injection Add the auth proxy sidecar infrastructure for TLS MITM credential injection: - New DonkeyWork.CodeSandbox.AuthProxy project: C# forward proxy with CONNECT handling, TLS MITM for allowlisted domains, domain blocking, and dynamic certificate generation signed by an internal CA - CA certificate generation: bash script (scripts/generate-ca.sh) and in-code ephemeral CA fallback for development - Sidecar Docker image with multi-stage build, non-root user, health checks - Executor image updated with entrypoint.sh to trust mounted proxy CA certs - BuildPodSpec and BuildWarmPodSpec updated to inject auth-proxy sidecar container with CA cert volumes, proxy env vars, and readiness probes (gated behind EnableAuthProxy config flag, default false) - KataContainerManager config extended with auth proxy settings - CI/CD workflows updated to build and publish the new authproxy image - Unit tests for domain matching and certificate generation https://claude.ai/code/session_01E8WpfFMR2iTr4wFLa14w8h
7f2e8cb to
20d15ce
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add the auth proxy sidecar infrastructure for TLS MITM credential injection:
handling, TLS MITM for allowlisted domains, domain blocking, and dynamic
certificate generation signed by an internal CA
ephemeral CA fallback for development
container with CA cert volumes, proxy env vars, and readiness probes
(gated behind EnableAuthProxy config flag, default false)
https://claude.ai/code/session_01E8WpfFMR2iTr4wFLa14w8h