Skip to content

docs(rfc): propose sandbox proxy egress adapter model#1511

Draft
johntmyers wants to merge 1 commit into
mainfrom
0004-sandbox-proxy-egress-adapter/jm
Draft

docs(rfc): propose sandbox proxy egress adapter model#1511
johntmyers wants to merge 1 commit into
mainfrom
0004-sandbox-proxy-egress-adapter/jm

Conversation

@johntmyers
Copy link
Copy Markdown
Collaborator

Summary

Proposes an RFC for remodeling sandbox proxy egress around transport adapters, a shared egress intent/decision boundary, and relay-owned protocol parsing/dialing.

Related Issue

None.

Changes

  • Adds RFC 0004 for the sandbox proxy egress adapter model.
  • Documents current proxy shape, including nftables bypass enforcement and current forward-proxy mitigation behavior.
  • Splits technical details and implementation phases into appendix files.
  • Covers CONNECT, forward HTTP, policy DNS, transparent TCP, local service adapters, WebSocket handling, and request-body credential rewrite.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

Not run; RFC/documentation draft only. A pre-commit run was started and then intentionally stopped because this is a draft RFC.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
@copy-pr-bot
Copy link
Copy Markdown

copy-pr-bot Bot commented May 21, 2026

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant