Repository navigation
feat: exclusive workload TLS gateway for Hermes and Rust 1.99 - #68
Conversation
ak5
left a comment
There was a problem hiding this comment.
Implementation review of d0dd671 is recorded in docs/security-review-workload-gateway.md. This is the implementing agent's review, not an independent security audit.
Reviewed exact-host routing, CONNECT/SNI/HTTP authority agreement, per-request grants, signed-mode preservation, provider lookup ordering, policy-owned typed sinks, DNS pinning/private-address denial, verified upstream TLS, redirect isolation, session forwarding, bounded streaming, compression/upgrade denial, receipts and fixed logs/errors. No unresolved findings remain in that review. The synthetic example validates using the actual CLI, relative Markdown links pass, and final mise run check passes on Rust 1.99.0. The full 18-test pinned Hermes compatibility check passes locally and in Linux CI.
Remaining release gate: all PR CI checks, including unmodified gh on Linux and production gateway image build, must pass on this exact head. Infra network isolation, installed client CA trust and origin-side hydration, IPv6/QUIC/alternate-route denial, config CD, separate admission, encrypted backups and operator cutover remain outside this PR. The convergence guard must remain until those checks are complete.
ak5
left a comment
There was a problem hiding this comment.
Final-head review: e7bcf5f changes only the two unavailable Alpine CA/curl fixture pins after the recorded source review. Final mise run check and all current-head GitHub checks pass, including Linux unmodified curl/gh, Hermes, dependency policy, images and CodeQL. No unresolved review findings; Infra isolation/trust/cutover limitations remain as documented.
Summary
Add a separate, fixed-workload explicit proxy for ordinary Hermes, curl, gh and SDK clients. Every permitted HTTPS connection terminates at Charon, and every operation on reused HTTP/1.1 or HTTP/2 connections is authorized before forwarding or credential lookup.
Motivation and scope
The signed single-use manifest and single-service transparent listeners cannot serve ordinary unmodified proxy clients. This gateway uses exclusive network isolation as its identity boundary, with exact-host deny-default grants, verified public-only upstream TLS/DNS, closed credential sinks, and bounded streaming. Existing signed proxy and independent Hermes tool admission remain compatible. Upgrade the complete Rust toolchain/build pins to 1.99.0 and fix the existing Rustls advisory with 0.23.45.
No live infrastructure, Ansible convergence guard, deployment, or cutover changes are included.
The image gate also exposed unavailable CA/curl package pins in the existing Alpine gh workload fixture. Refresh those two exact pins to the repository's available versions; keep its base image and gh pin unchanged.
Security impact
docs/threat-model.md, contract, ADR and implementation review describe isolation, trust, streaming, logging and residual risks.docs/security-review-workload-gateway.md; no independent audit is claimed. No unresolved source-review findings remain.Documentation
Schema-valid synthetic
examples/hermes-gateway.toml, exact provider inventory, CA/proxy requirements, feature verification, rollback and Infra handoff are documented. Documentation/code parity and relative Markdown links pass.Verification
mise run checkon Rust 1.99.0: formatting, Clippy, all Rust tests, deployment contract, dependency policy and Hermes integration.SSL_CERT_FILE; Linux CI must pass the unmodified gh proof. Certificate verification is never disabled.Risk and rollback