Skip to main content

ProxyConfig

Struct ProxyConfig 

Source
pub struct ProxyConfig {
    pub bind_addr: IpAddr,
    pub bind_port: u16,
    pub allowed_hosts: Vec<String>,
    pub routes: Vec<RouteConfig>,
    pub external_proxy: Option<ExternalProxyConfig>,
    pub direct_connect_ports: Vec<u16>,
    pub max_connections: usize,
    pub intercept_ca_dir: Option<PathBuf>,
    pub intercept_parent_ca_pems: Option<Vec<u8>>,
}
Expand description

Configuration for the proxy server.

Fields§

§bind_addr: IpAddr

Bind address (default: 127.0.0.1)

§bind_port: u16

Bind port (0 = OS-assigned ephemeral port)

§allowed_hosts: Vec<String>

Allowed hosts for CONNECT mode (exact match + wildcards). Empty = allow all hosts (except deny list).

§routes: Vec<RouteConfig>

Reverse proxy credential routes.

§external_proxy: Option<ExternalProxyConfig>

External (enterprise) proxy URL for passthrough mode. When set, CONNECT requests are chained to this proxy.

§direct_connect_ports: Vec<u16>

Outbound TCP ports that the sandbox allows direct connections on (via Landlock ConnectTcp). Hosts whose resolved port is NOT in this set must go through the proxy and should NOT appear in NO_PROXY.

§max_connections: usize

Maximum concurrent connections (0 = unlimited).

§intercept_ca_dir: Option<PathBuf>

Directory the proxy will write the TLS-intercept trust bundle into.

When set together with at least one route requiring L7 visibility (endpoint_rules, credential_key, or oauth2), the proxy generates an ephemeral session CA and writes a PEM bundle (system roots + optional parent SSL_CERT_FILE + ephemeral CA) into this directory at startup. The path is exposed via ProxyHandle::intercept_ca_path() so the CLI can grant the sandboxed child a Landlock/Seatbelt read capability for it.

The directory must exist and be owner-only readable (mode 0o700) before start() is called. The CLI conventionally points this at ~/.nono/sessions/<session_id>/.

None disables TLS interception entirely; CONNECT requests behave as before (transparent tunnel for non-route hosts; 403 for routes without L7 requirements).

§intercept_parent_ca_pems: Option<Vec<u8>>

Optional contents of the parent process’s SSL_CERT_FILE, merged into the trust bundle so any corporate CA configured on the host remains trusted by the sandboxed child.

The CLI reads this from std::env::var("SSL_CERT_FILE") and std::fs::read(...) before calling start(). Skipped during (de)serialisation: it’s not part of any user-authored config file.

Trait Implementations§

Source§

impl Clone for ProxyConfig

Source§

fn clone(&self) -> ProxyConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ProxyConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for ProxyConfig

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for ProxyConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for ProxyConfig

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,