Expand description
§ironflow-auth-proxy
HTTP service that keeps the Claude credential out of ironflow agent pods.
The worker (K8sEphemeralProvider::auth_proxy) asks the admin API for an
opaque token bound to one run and one step, and hands only that token to
the pod. Claude Code sends it as Authorization: Bearer to this proxy,
which swaps it for the real credential and relays the request to
api.anthropic.com, streaming the answer back.
One listener serves:
GET /healthz- liveness;/admin/v1/...- token issuance and revocation, behindAuthorization: Bearer <IRONFLOW_AUTH_PROXY_ADMIN_KEY>;- anything else - the relay: an unknown, expired or revoked token gets a
401, a path outside
/v1/or a request for another host a 403, a method other than GET/POST a 405.
Tokens live in memory: run a single replica. Logs never contain a token or a credential, only the short token id.
§Examples
use std::time::Duration;
use ironflow_auth_proxy::{AuthProxyConfig, AuthProxyState, serve, spawn_purge};
use tokio::net::TcpListener;
let state = AuthProxyState::new(AuthProxyConfig::new("0123456789abcdef0123456789abcdef"))?;
let purge = spawn_purge(state.registry().clone(), Duration::from_secs(60));
let listener = TcpListener::bind("0.0.0.0:8080").await?;
serve(listener, state).await?;
purge.abort();Structs§
- Auth
Proxy Config - Configuration of the proxy. Its
Debugoutput never shows the admin key. - Auth
Proxy State - Shared state of the proxy: the token registry, the configuration and the upstream HTTP client. Cheap to clone.
Constants§
- DEFAULT_
MAX_ BODY_ BYTES - Default largest request body relayed: 32 MiB.
- MIN_
ADMIN_ KEY_ LEN - Shortest admin key accepted.
Functions§
- router
- The proxy router: health, admin API and relay.
- serve
- Serve the proxy on
listeneruntil ctrl-c or SIGTERM, letting in-flight requests finish. - spawn_
purge - Spawn a task dropping the expired grants of
registryeveryinterval.