Skip to content

Add an extra crate providing an attested TLS TCP tunnel - #179

Closed
ameba23 wants to merge 4 commits into
mainfrom
peg/tcp-tunnel
Closed

ameba23 wants to merge 4 commits into
mainfrom
peg/tcp-tunnel

Conversation

@ameba23

@ameba23 ameba23 commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

This adds an additional simpler version of the proxy which does not care about applicaiton protocol - it just provides a byte-stream over an attested TLS tunnel.

Since this involved adding an extra crate i move some helper functions for self signed certs to the attested-tls crate, as these are used by both the TCP tunnel and existing http proxy.

Closes #54

@ameba23
ameba23 marked this pull request as draft September 29, 2026 09:12
@@ -0,0 +1,324 @@
use std::{net::IpAddr, sync::Arc};

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Refactor - As mentioned in PR description, this stuff was moved from the http to here as it is needed by both the new TCP tunnel and the existing http proxy

Comment thread attested-tls/Cargo.toml
[dependencies]
tokio = { version = "1.48.0", features = ["full"] }
tokio-rustls = { version = "0.26.4", default-features = false }
tokio = { workspace = true, features = ["io-util", "net", "rt"] }

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not strictly related to PR - i pruned tokio features to only the required ones, not full

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Removing the public normalize_pem module breaks the existing 1.x library API.

Review effort: Balanced
Findings: 1 Medium severity · 2 Low severity

Open (3)
What changed in this PR

Adds a protocol-agnostic TCP tunnel over attested TLS and centralizes shared TLS helpers.

Changes:

  • Adds TCP tunnel client/server APIs, CLI, lifecycle controls, and TLS configuration.
  • Adds integration coverage for streaming, gRPC, shutdown, capacity, and CLI behavior.
  • Moves self-signed helpers into attested-tls and simplifies private-key loading.
File Description
tcp-tunnel/​src/​lib.rs Implements tunnel forwarding and lifecycle management.
tcp-tunnel/​src/​main.rs Adds the tunnel CLI.
tcp-tunnel/​src/​tls.rs Builds client and server TLS configurations.
tcp-tunnel/​Cargo.toml Defines the new crate.
tcp-tunnel/​README.md Documents tunnel usage and security.
tcp-tunnel/​tests/​common/​mod.rs Provides shared test infrastructure.
tcp-tunnel/​tests/​tunnel.rs Tests tunnel behavior and attestation.
tcp-tunnel/​tests/​grpc.rs Tests opaque gRPC forwarding.
tcp-tunnel/​tests/​cli.rs Tests CLI and operational behavior.
attested-tls/​src/​self_signed.rs Hosts shared self-signed helpers.
attested-tls/​src/​lib.rs Exposes the optional helper module.
attested-tls/​Cargo.toml Adds the self-signed feature.
attested-tls/​README.md Documents the feature.
src/​self_signed.rs Preserves the proxy re-export.
src/​normalize_pem.rs Removes the key-normalization implementation.
src/​main.rs Uses native Rustls PEM key parsing.
src/​lib.rs Removes the public normalization module.
Cargo.toml Adds workspace dependencies and the tunnel member.
Cargo.lock Records dependency changes.
README.md Links to the TCP tunnel.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/lib.rs
@@ -2,7 +2,6 @@
pub mod attested_get;
pub mod file_server;
pub mod health_check;

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Im not concerned about this. No-one currently depending on this as a library crate - only binary.

Comment thread README.md
- `attested-tls-proxy attested-file-server` - serve files from a local filesystem path over an attested TLS channel.
- `attested-tls-proxy attested-get` - connect to a proxy server, verify its attestation, make a single HTTP GET request, and write the response body to standard output.

If you rather want opaque TCP forwarding, see [`attested-tls-tcp-tunnel`](tcp-tunnel/README.md). It provides a separate CLI and library with one attested connection per source TCP connection.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like my human made grammatical errors actually


use crate::{AttestedTlsError, TlsCertAndKey};

/// Generate a self signed certifcate
@ameba23

ameba23 commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Closing in favor of #183

@ameba23 ameba23 closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Consider making raw TLS over TCP based proxy

2 participants