Conversation
| @@ -0,0 +1,324 @@ | |||
| use std::{net::IpAddr, sync::Arc}; | |||
There was a problem hiding this comment.
Refactor - As mentioned in PR description, this stuff was moved from the http to here as it is needed by both the new TCP tunnel and the existing http proxy
| [dependencies] | ||
| tokio = { version = "1.48.0", features = ["full"] } | ||
| tokio-rustls = { version = "0.26.4", default-features = false } | ||
| tokio = { workspace = true, features = ["io-util", "net", "rt"] } |
There was a problem hiding this comment.
Not strictly related to PR - i pruned tokio features to only the required ones, not full
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Removing the public normalize_pem module breaks the existing 1.x library API.
Review effort: Balanced
Findings: 1
Open (3)
What changed in this PR
Adds a protocol-agnostic TCP tunnel over attested TLS and centralizes shared TLS helpers.
Changes:
- Adds TCP tunnel client/server APIs, CLI, lifecycle controls, and TLS configuration.
- Adds integration coverage for streaming, gRPC, shutdown, capacity, and CLI behavior.
- Moves self-signed helpers into
attested-tlsand simplifies private-key loading.
| File | Description |
|---|---|
tcp-tunnel/src/lib.rs |
Implements tunnel forwarding and lifecycle management. |
tcp-tunnel/src/main.rs |
Adds the tunnel CLI. |
tcp-tunnel/src/tls.rs |
Builds client and server TLS configurations. |
tcp-tunnel/Cargo.toml |
Defines the new crate. |
tcp-tunnel/README.md |
Documents tunnel usage and security. |
tcp-tunnel/tests/common/mod.rs |
Provides shared test infrastructure. |
tcp-tunnel/tests/tunnel.rs |
Tests tunnel behavior and attestation. |
tcp-tunnel/tests/grpc.rs |
Tests opaque gRPC forwarding. |
tcp-tunnel/tests/cli.rs |
Tests CLI and operational behavior. |
attested-tls/src/self_signed.rs |
Hosts shared self-signed helpers. |
attested-tls/src/lib.rs |
Exposes the optional helper module. |
attested-tls/Cargo.toml |
Adds the self-signed feature. |
attested-tls/README.md |
Documents the feature. |
src/self_signed.rs |
Preserves the proxy re-export. |
src/normalize_pem.rs |
Removes the key-normalization implementation. |
src/main.rs |
Uses native Rustls PEM key parsing. |
src/lib.rs |
Removes the public normalization module. |
Cargo.toml |
Adds workspace dependencies and the tunnel member. |
Cargo.lock |
Records dependency changes. |
README.md |
Links to the TCP tunnel. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @@ -2,7 +2,6 @@ | |||
| pub mod attested_get; | |||
| pub mod file_server; | |||
| pub mod health_check; | |||
There was a problem hiding this comment.
Im not concerned about this. No-one currently depending on this as a library crate - only binary.
| - `attested-tls-proxy attested-file-server` - serve files from a local filesystem path over an attested TLS channel. | ||
| - `attested-tls-proxy attested-get` - connect to a proxy server, verify its attestation, make a single HTTP GET request, and write the response body to standard output. | ||
|
|
||
| If you rather want opaque TCP forwarding, see [`attested-tls-tcp-tunnel`](tcp-tunnel/README.md). It provides a separate CLI and library with one attested connection per source TCP connection. |
There was a problem hiding this comment.
I like my human made grammatical errors actually
|
|
||
| use crate::{AttestedTlsError, TlsCertAndKey}; | ||
|
|
||
| /// Generate a self signed certifcate |
|
Closing in favor of #183 |


This adds an additional simpler version of the proxy which does not care about applicaiton protocol - it just provides a byte-stream over an attested TLS tunnel.
Since this involved adding an extra crate i move some helper functions for self signed certs to the attested-tls crate, as these are used by both the TCP tunnel and existing http proxy.
Closes #54