| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
A unidirectional TCP to Unix socket proxy with TLS encryption and Ed25519 authentication for TDX environments.
This proxy allows authenticated clients to stream data into a container through a Unix socket. It provides:
sequenceDiagram
participant C as TLS Client
participant P as TLS Proxy
participant U as Unix Socket
participant Co as Container
Note over C,Co: TLS Handshake with mTLS
C->>P: TLS Connect (port 27018)
P->>C: Server Certificate (self-signed)
C->>P: Client Certificate (from SSH key)
P->>P: Extract Ed25519 pubkey from cert
P->>P: Compare with /etc/searcher_key
alt Public Key Matches
P->>C: TLS Handshake Complete
else Public Key Mismatch
P->>C: TLS Alert: AccessDenied
P--xC: Close connection
end
Note over C,Co: Encrypted Data Transfer (Timing Isolated)
Note over C,P: ✅ Data is TLS encrypted
C->>P: Stream encrypted data
P->>P: Decrypt & buffer in channel
P->>U: Forward plaintext
U->>Co: Deliver to container
C--xP: TLS close
cargo build --release# Basic usage with defaults
./target/release/input-only-proxy
# Custom configuration
./target/release/input-only-proxy \
--listen 0.0.0.0:27018 \
--unix-socket /persistent/input/input.sock \
--pubkey-file /etc/searcher_key \ # SSH public key (ed25519)
--cert-base-path /persistent/input-proxy# Step 1: Convert SSH key to TLS certificate (one time)
./scripts/ssh_to_tls_cert.py ~/.ssh/id_ed25519 client-cert.pem
# Step 2: Connect with TLS client (accepts any server certificate)
cargo run --example tls_client -- 127.0.0.1:27018 client-cert.pem
# Alternative: Connect with server certificate verification
cargo run --example tls_client -- 127.0.0.1:27018 client-cert.pem server.crtcargo run --example unix_listenercargo run -- \
--unix-socket /tmp/test_input.sock \
--pubkey-file ~/.ssh/id_ed25519.pub \
--cert-base-path /tmp/test-proxy# Generate certificate (one time)
./ssh_to_tls_cert.py ~/.ssh/id_ed25519 client-cert.pem
# Connect (accepts any server certificate)
cargo run --example tls_client -- 127.0.0.1:27018 client-cert.pem
# Alternative: Connect with server certificate verification
cargo run --example tls_client -- 127.0.0.1:27018 client-cert.pem /tmp/test-proxy.crt| Flag | Default | Description |
|---|---|---|
| --listen | 0.0.0.0:27018 | TLS address to listen on |
| --unix-socket | /persistent/input/input.sock | Unix socket path to forward to |
| --pubkey-file | /etc/searcher_key | SSH Ed25519 public key file |
| --cert-base-path | /persistent/input-proxy | Base path for certificate (.crt) and key (.key) files (auto-generated if missing) |
| --log-level | info | Logging level (via RUST_LOG env var) |
MIT
| Back | FazBrowse Home | New Git URL |