Skip to content

feat: exclusive workload TLS gateway for Hermes and Rust 1.99 - #68

Merged
ak5 merged 2 commits into
devfrom
feat/hermes-workload-proxy
Oct 3, 2026
Merged

ak5 merged 2 commits into
devfrom
feat/hermes-workload-proxy

Conversation

@ak5

@ak5 ak5 commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

Add a separate, fixed-workload explicit proxy for ordinary Hermes, curl, gh and SDK clients. Every permitted HTTPS connection terminates at Charon, and every operation on reused HTTP/1.1 or HTTP/2 connections is authorized before forwarding or credential lookup.

Motivation and scope

The signed single-use manifest and single-service transparent listeners cannot serve ordinary unmodified proxy clients. This gateway uses exclusive network isolation as its identity boundary, with exact-host deny-default grants, verified public-only upstream TLS/DNS, closed credential sinks, and bounded streaming. Existing signed proxy and independent Hermes tool admission remain compatible. Upgrade the complete Rust toolchain/build pins to 1.99.0 and fix the existing Rustls advisory with 0.23.45.

No live infrastructure, Ansible convergence guard, deployment, or cutover changes are included.

The image gate also exposed unavailable CA/curl package pins in the existing Alpine gh workload fixture. Refresh those two exact pins to the repository's available versions; keep its base image and gh pin unchanged.

Security impact

  • Trust boundary changed: yes; separate network-bound fixed realm/workload and universal permitted HTTPS interception.
  • Credential flow changed: yes; secretless grants never query providers, while policy-owned header/Basic sinks require canonical capability references before lookup. Explicit caller-owned OAuth/API/session forwarding remains available.
  • Threat model updated: docs/threat-model.md, contract, ADR and implementation review describe isolation, trust, streaming, logging and residual risks.
  • Review: Codex source/test review in docs/security-review-workload-gateway.md; no independent audit is claimed. No unresolved source-review findings remain.

Documentation

Schema-valid synthetic examples/hermes-gateway.toml, exact provider inventory, CA/proxy requirements, feature verification, rollback and Infra handoff are documented. Documentation/code parity and relative Markdown links pass.

Verification

  • mise run check on Rust 1.99.0: formatting, Clippy, all Rust tests, deployment contract, dependency policy and Hermes integration.
  • Pinned Hermes source compatibility: all 18 integration tests pass with the upstream interface available.
  • Real local downstream/upstream TLS fixtures: denial before lookup, no secretless lookup, typed hydration, connection reuse, HTTP/2, authority/SNI disagreement, upstream trust, private DNS, streaming, uploads/downloads, compression/upgrade denial, and sentinel-safe logs/errors/receipts.
  • Local unmodified curl proof passes. gh's local fixture is Linux-only because existing macOS Go/gh uses Keychain rather than SSL_CERT_FILE; Linux CI must pass the unmodified gh proof. Certificate verification is never disabled.

Risk and rollback

  • Risk: exclusive isolation and workload CA distribution are Infra obligations; a shared listener is prohibited. HTTP/3, WebSockets and compression fail closed. Process-lifetime public IPv4 pins require restart for DNS changes. Streaming cannot retract partial side effects or recognize arbitrary secret transformations.
  • Rollback: retain and restore installed layout, image pins and config revision, preserving egress isolation. Keep full convergence guarded until Infra validates the immutable release, actual traffic, bypass denial, config CD, admission and encrypted backups, then requests operator cutover authorization.

@ak5 ak5 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implementation review of d0dd671 is recorded in docs/security-review-workload-gateway.md. This is the implementing agent's review, not an independent security audit.

Reviewed exact-host routing, CONNECT/SNI/HTTP authority agreement, per-request grants, signed-mode preservation, provider lookup ordering, policy-owned typed sinks, DNS pinning/private-address denial, verified upstream TLS, redirect isolation, session forwarding, bounded streaming, compression/upgrade denial, receipts and fixed logs/errors. No unresolved findings remain in that review. The synthetic example validates using the actual CLI, relative Markdown links pass, and final mise run check passes on Rust 1.99.0. The full 18-test pinned Hermes compatibility check passes locally and in Linux CI.

Remaining release gate: all PR CI checks, including unmodified gh on Linux and production gateway image build, must pass on this exact head. Infra network isolation, installed client CA trust and origin-side hydration, IPv6/QUIC/alternate-route denial, config CD, separate admission, encrypted backups and operator cutover remain outside this PR. The convergence guard must remain until those checks are complete.

@ak5 ak5 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final-head review: e7bcf5f changes only the two unavailable Alpine CA/curl fixture pins after the recorded source review. Final mise run check and all current-head GitHub checks pass, including Linux unmodified curl/gh, Hermes, dependency policy, images and CodeQL. No unresolved review findings; Infra isolation/trust/cutover limitations remain as documented.

@ak5
ak5 merged commit 3d3a4d8 into dev Oct 3, 2026
9 checks passed
@ak5
ak5 deleted the feat/hermes-workload-proxy branch October 3, 2026 17:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant