Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
97 commits
Select commit Hold shift + click to select a range
4f7ab23
Initial release: Lightweight OpenAI-compatible proxy for Maple/OpenSe…
AnthonyRonning Aug 25, 2025
6c2e287
feat: Initial implementation of Maple Proxy OpenAI-compatible server
AnthonyRonning Aug 27, 2025
9a74b72
Create LICENSE
AnthonyRonning Aug 27, 2025
b1930be
fix: Preserve .env variables when using run-with-backend commands
AnthonyRonning Aug 28, 2025
b4010e6
chore: Update to official OpenSecret SDK v0.2.0
AnthonyRonning Aug 28, 2025
441f86b
feat: Add production-ready Docker deployment configuration
AnthonyRonning Aug 29, 2025
cbc1558
feat: Add GitHub Container Registry (GHCR) automated deployment
AnthonyRonning Aug 29, 2025
b3ab048
fix: Add Cargo.lock for reproducible binary builds
AnthonyRonning Aug 29, 2025
4df2a47
fix: Install cargo-machete before running dependency check
AnthonyRonning Aug 29, 2025
13b5366
perf: Add caching for cargo tools in GitHub Actions
AnthonyRonning Aug 29, 2025
ad832c8
perf: Optimize CI/CD with native ARM runners and dependency cleanup
AnthonyRonning Aug 29, 2025
8bdca99
fix: Remove conflicting tags from Docker push-by-digest workflow
AnthonyRonning Aug 29, 2025
72190a2
fix: Use lowercase repository name for Docker registry
AnthonyRonning Aug 29, 2025
d5fb9ff
chore: Add fail-fast: false to Docker build matrix
AnthonyRonning Aug 29, 2025
80e5849
perf: Disable code coverage job until test coverage improves
AnthonyRonning Aug 29, 2025
cbed208
fix: Separate Docker cache scopes per platform
AnthonyRonning Aug 29, 2025
1bb0f2f
Add claude.md file
AnthonyRonning Aug 29, 2025
572fe72
feat: Add library support for embedding Maple Proxy in Rust applications
AnthonyRonning Aug 29, 2025
025b35c
feat: Add crates.io metadata for package discovery
AnthonyRonning Aug 29, 2025
82eb8a3
chore: Optimize tokio dependencies and bump version to 0.1.1
AnthonyRonning Aug 30, 2025
409d535
chore: Update Cargo.lock for version 0.1.1
AnthonyRonning Aug 30, 2025
96e3030
Bump sdk to 0.2.1
AnthonyRonning Sep 12, 2025
89fc372
Merge pull request #1 from OpenSecretCloud/bump-rust-0-2-1
AnthonyRonning Sep 12, 2025
bc44958
Bump to 0.1.2
AnthonyRonning Sep 12, 2025
0ceb0a8
Bump SDK to 0.2.2 (adds tool calling support)
AnthonyRonning Oct 27, 2025
9fe297d
Fix security vulnerability in tracing-subscriber
AnthonyRonning Oct 28, 2025
17ea7cb
Merge pull request #2 from OpenSecretCloud/bump-sdk-0-2-2
AnthonyRonning Oct 28, 2025
3b19d19
Bump to 0.1.3
AnthonyRonning Oct 28, 2025
734cc16
Fix invalid Docker tag format for tag events
AnthonyRonning Oct 28, 2025
a37fbbe
bump to opensecret 0.2.3
AnthonyRonning Nov 18, 2025
e88078d
Update security audit to use official rustsec/audit-check action
AnthonyRonning Dec 24, 2025
a8fb0f2
Add checks:write permission for rustsec/audit-check action
AnthonyRonning Dec 24, 2025
4880aed
feat: add OpenAI-compatible embeddings endpoint
AnthonyRonning Dec 31, 2025
d8e1945
Add issues:write permission for rustsec/audit-check action
AnthonyRonning Dec 31, 2025
3dcf7b7
Merge pull request #4 from OpenSecretCloud/feat/embeddings-api
AnthonyRonning Dec 31, 2025
0115263
chore: bump version to 0.1.5
AnthonyRonning Dec 31, 2025
a1ac8a8
chore: bump opensecret to 0.2.8
AnthonyRonning Jan 27, 2026
6d7bcb2
Merge pull request #6 from OpenSecretCloud/chore/bump-opensecret-0.2.8
AnthonyRonning Jan 27, 2026
89ddec5
chore: bump version to 0.1.6
AnthonyRonning Jan 27, 2026
6c82fc9
fix: update time crate to 0.3.47 (RUSTSEC-2026-0009)
AnthonyRonning Feb 9, 2026
8ba3d06
fix: update bytes crate to 1.11.1 (RUSTSEC-2026-0007)
AnthonyRonning Feb 9, 2026
a4c7136
Merge pull request #10 from OpenSecretCloud/fix/rustsec-2026-0009-tim…
AnthonyRonning Feb 9, 2026
590d67e
feat: add OpenClaw plugin for seamless maple-proxy integration (#13)
AnthonyRonning Feb 17, 2026
7c72ef6
docs: remove outdated beta install note from README (#16)
AnthonyRonning Feb 17, 2026
7f9fee5
fix: upgrade opensecret SDK to 0.2.9 for streaming tool call passthrough
AnthonyRonning Feb 21, 2026
38c1dd1
Merge pull request #17 from OpenSecretCloud/fix/streaming-tool-call-p…
AnthonyRonning Feb 21, 2026
b24bce1
chore: bump version to 0.1.7
AnthonyRonning Feb 21, 2026
2955cd2
fix: update Rust dependencies for security advisories
AnthonyRonning Apr 24, 2026
ae1082d
docs: remove pinned opensecret guidance
AnthonyRonning Apr 24, 2026
725ce69
Merge pull request #27 from OpenSecretCloud/chore/update-rust-deps
AnthonyRonning Apr 24, 2026
87b9237
fix: update opensecret SDK to 3.1.1
AnthonyRonning Apr 25, 2026
47255e2
Merge pull request #28 from OpenSecretCloud/fix/update-opensecret-3-1-1
AnthonyRonning Apr 25, 2026
4c8d7c2
chore: bump version to 0.1.8
AnthonyRonning Apr 25, 2026
ccfd26b
Harden GitHub Actions workflows
AnthonyRonning May 21, 2026
2984f95
Merge pull request #30 from OpenSecretCloud/chore/harden-github-actions
AnthonyRonning May 21, 2026
811fa2c
Cache OpenSecret clients per API key
AnthonyRonning Jun 3, 2026
c5e06e8
Bound OpenSecret client cache
AnthonyRonning Jun 3, 2026
34a8e7a
Merge pull request #34 from OpenSecretCloud/fix/cache-opensecret-clients
AnthonyRonning Jun 3, 2026
cec2b68
Add configurable backend timeouts
AnthonyRonning Jun 3, 2026
499129a
Address timeout review feedback
AnthonyRonning Jun 3, 2026
82cfecb
Document timeout env vars in guidance
AnthonyRonning Jun 3, 2026
5b5d646
Merge pull request #35 from OpenSecretCloud/fix/configurable-timeouts
AnthonyRonning Jun 3, 2026
41cf9f2
chore: bump version to 0.1.9
AnthonyRonning Jun 4, 2026
7a5c881
Document embeddings endpoint
AnthonyRonning Jun 13, 2026
5633020
Merge pull request #38 from OpenSecretCloud/codex/document-embeddings…
AnthonyRonning Jun 13, 2026
109d948
Raise proxy request body limit
AnthonyRonning Jun 15, 2026
c5bf3fe
Merge pull request #39 from OpenSecretCloud/codex-maple-proxy-payload…
AnthonyRonning Jun 15, 2026
0c2788b
chore: bump version to 0.1.10
AnthonyRonning Jun 15, 2026
bc691fd
Update OpenSecret SDK to 3.3.0
AnthonyRonning Jul 11, 2026
331df67
Update quinn-proto to 0.11.15
AnthonyRonning Jul 11, 2026
4123f7f
Merge pull request #42 from OpenSecretCloud/codex-embeddings-api-inve…
AnthonyRonning Jul 11, 2026
22f0272
Allow security audit to open issues
AnthonyRonning Jul 11, 2026
b97f8d7
Merge pull request #43 from OpenSecretCloud/codex-maple-proxy-audit-i…
AnthonyRonning Jul 11, 2026
458c0ff
chore: bump version to 0.1.11
AnthonyRonning Jul 11, 2026
0aed11b
Merge pull request #44 from OpenSecretCloud/codex-maple-proxy-v0-1-11…
AnthonyRonning Jul 11, 2026
379a9d8
Update anyhow to 1.0.103
AnthonyRonning Jul 12, 2026
08ff3c8
chore: bump version to 0.1.12
AnthonyRonning Jul 12, 2026
04c3ada
Merge pull request #46 from OpenSecretCloud/codex-maple-proxy-securit…
AnthonyRonning Jul 12, 2026
40eadb0
feat: add lossless inference proxy transport
AnthonyRonning Jul 13, 2026
908ae76
Merge pull request #47 from OpenSecretCloud/codex-maple-agent-read-pe…
AnthonyRonning Jul 13, 2026
a33ee3e
feat: scope PCR0 trust by environment
AnthonyRonning Aug 11, 2026
040869f
Merge pull request #49 from OpenSecretCloud/codex-pcr-env-binding-map…
AnthonyRonning Aug 11, 2026
8a2f2c1
chore: bump maple-proxy to 0.3.1
AnthonyRonning Aug 12, 2026
9e44ade
Merge pull request #50 from OpenSecretCloud/codex-maple-proxy-sdk-3-6…
AnthonyRonning Aug 12, 2026
9c24761
security: block compromised Rust crates
AnthonyRonning Aug 20, 2026
84d2082
security: update h2 past RUSTSEC-2026-0258
AnthonyRonning Aug 20, 2026
f7087dc
Merge pull request #52 from OpenSecretCloud/codex-cargo-deny-wave-map…
AnthonyRonning Aug 20, 2026
64fdb9f
ci: enforce locked dependency resolution
AnthonyRonning Aug 21, 2026
aafd538
Merge pull request #53 from OpenSecretCloud/codex-cargo-locked-maple-…
AnthonyRonning Aug 21, 2026
e314ce4
security: enforce daily RustSec checks
AnthonyRonning Aug 21, 2026
85de75a
Merge pull request #54 from OpenSecretCloud/codex-cargo-audit-maple-p…
AnthonyRonning Aug 22, 2026
f5f756a
security: enforce unsoundness advisories
AnthonyRonning Aug 22, 2026
fbe9d3d
Merge pull request #55 from OpenSecretCloud/codex-cargo-unsound-maple…
AnthonyRonning Aug 22, 2026
d54cb26
chore: bump proxy to 0.3.2
AnthonyRonning Aug 22, 2026
7b89422
Merge pull request #56 from OpenSecretCloud/codex-proxy-032-maple-proxy
AnthonyRonning Aug 22, 2026
f411ca2
Add 'proxy/' from commit '7b89422cf2ac22a6829161f99f6a2cce14142a8c'
AnthonyRonning Aug 26, 2026
9df7e3c
chore: remove inert nested proxy workflows
AnthonyRonning Aug 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 55 additions & 0 deletions proxy/.dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# Git
.git
.gitignore

# Build artifacts
target/
Dockerfile
.dockerignore

# Development files
.env
.env.local
*.log
*.pid
*.swp
*.swo
*~

# IDE
.vscode/
.idea/
*.iml

# Documentation
README.md
LICENSE
docs/

# CI/CD
.github/
.gitlab-ci.yml
.travis.yml

# Test coverage
tarpaulin-report.html
cobertura.xml
coverage/

# Nix
flake.nix
flake.lock
result
result-*

# Development scripts
justfile
setup-hooks.sh

# macOS
.DS_Store

# Temporary files
tmp/
temp/
*.tmp
36 changes: 36 additions & 0 deletions proxy/.env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Maple Proxy Configuration
# Copy this file to .env and fill in your values

# Server Configuration
MAPLE_HOST=127.0.0.1
MAPLE_PORT=8080

# Maple Backend Configuration
# Production: https://enclave.trymaple.ai
# Development: https://enclave.secretgpt.ai
# Local: http://localhost:3000
MAPLE_BACKEND_URL=https://enclave.trymaple.ai

# PCR0 trust roots must match the selected backend environment.
# Use development only with the development enclave; production is the default.
MAPLE_PCR0_ENVIRONMENT=production

# Authentication
# Your Maple API key - get this from https://trymaple.ai
MAPLE_API_KEY=your-maple-api-key-here

# Debugging
MAPLE_DEBUG=false

# CORS (enable for web applications)
# Recommended: true for Docker deployments
MAPLE_ENABLE_CORS=true

# Timeouts
# Backend request setup and non-streaming response timeout, in seconds
MAPLE_REQUEST_TIMEOUT_SECS=300
# Maximum idle time between streaming chunks, in seconds
MAPLE_STREAM_IDLE_TIMEOUT_SECS=300

# Rust Logging (optional)
# RUST_LOG=info,maple_proxy=debug
68 changes: 68 additions & 0 deletions proxy/.githooks/pre-commit
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
#!/usr/bin/env bash
# Pre-commit hook for Maple Proxy
# Ensures code quality before commits

set -e

echo "🔍 Running pre-commit checks..."

# Check if we're in a git repository
if ! git rev-parse --git-dir >/dev/null 2>&1; then
echo "❌ Not in a git repository"
exit 1
fi

# Function to print step status
print_step() {
echo "📋 $1..."
}

print_success() {
echo "✅ $1"
}

print_error() {
echo "❌ $1"
}

# Rust formatting check
print_step "Checking Rust formatting"
if cargo fmt --check; then
print_success "Code formatting is correct"
else
print_error "Code formatting issues found"
echo "💡 Run 'cargo fmt' to fix formatting"
exit 1
fi

# Clippy linting
print_step "Running Clippy lints"
if cargo clippy --locked --all-targets --all-features -- -D warnings; then
print_success "Clippy checks passed"
else
print_error "Clippy lints failed"
echo "💡 Fix the issues above before committing"
exit 1
fi

# Cargo check (compilation)
print_step "Checking compilation"
if cargo check --locked --all-targets --all-features; then
print_success "Code compiles successfully"
else
print_error "Compilation failed"
exit 1
fi

# Run tests
print_step "Running tests"
if cargo test --locked --all-features; then
print_success "All tests passed"
else
print_error "Tests failed"
exit 1
fi

echo ""
echo "🎉 All pre-commit checks passed!"
echo " Ready to commit"
63 changes: 63 additions & 0 deletions proxy/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
# Rust
/target
# Note: Cargo.lock is committed for binaries (not libraries)
*.pdb

# Environment files
.env
.env.local
.env.development.local
.env.test.local
.env.production.local

# Claude IDE settings
.claude/

# Logs
logs
*.log
npm-debug.log*
yarn-debug.log*
yarn-error.log*

# IDE files
.vscode/
.idea/
*.swp
*.swo
*~

# OS files
.DS_Store
.DS_Store?
._*
.Spotlight-V100
.Trashes
ehthumbs.db
Thumbs.db

# Temporary files
*.tmp
*.temp

# API keys and secrets
secrets/
*.key
*.pem
*.crt

# Build artifacts
dist/
build/
out/

# Test coverage
coverage/
.nyc_output/

# Local development
.local/

# Backup files
*.bak
*.backup
101 changes: 101 additions & 0 deletions proxy/CLAUDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
# CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

## Project Overview

Maple Proxy is a lightweight OpenAI-compatible proxy server that forwards requests to Maple/OpenSecret's TEE (Trusted Execution Environment) infrastructure. It acts as a translation layer between OpenAI client libraries and the OpenSecret backend, enabling secure AI processing in trusted enclaves.

## Common Development Commands

### Build and Run
- `just run` - Start the development server (loads config from .env)
- `just run-local` - Run pointing to local backend (http://localhost:3000)
- `just run-prod` - Run pointing to production backend (https://enclave.trymaple.ai)
- `just build` - Build debug binary
- `just release` - Build optimized release binary
- `cargo run --locked` - Run directly with cargo

### Testing and Quality
- `just test` - Run all tests
- `just fmt` or `just format` - Format code with rustfmt
- `just lint` or `just clippy` - Run clippy lints with strict warnings
- `just check` - Run format, lint, and test in sequence

### Docker Operations
- `just docker-build` - Build Docker image locally
- `just docker-run` - Run container interactively
- `just docker-run-detached` - Run container in background
- `just compose-up` - Start with docker-compose
- `just compose-down` - Stop docker-compose services

## Architecture

### Core Components

1. **main.rs** - Entry point that initializes the server with configuration and starts the Axum web server on the configured host/port.

2. **lib.rs** - Library root that exports the main `create_app` function, which builds the Axum router with:
- Health check endpoints (/, /health)
- OpenAI-compatible endpoints (/v1/models, /v1/chat/completions)
- Optional CORS support
- Request tracing

3. **config.rs** - Configuration management using clap for CLI args and environment variables:
- Server settings (host, port)
- Backend URL configuration
- API key management
- Debug and CORS flags
- OpenAI-compatible error types

4. **proxy.rs** - Core proxy logic that:
- Extracts API keys from Authorization headers or falls back to default
- Creates OpenSecret client and performs attestation handshake
- Forwards requests to the TEE backend
- Handles streaming responses for chat completions
- Transforms responses to OpenAI format

### Request Flow

1. Client sends OpenAI-compatible request to proxy
2. Proxy extracts API key (from header or default config)
3. Creates OpenSecret client and performs TEE attestation
4. Forwards request to Maple backend (enclave.trymaple.ai or configured URL)
5. Streams response back to client in OpenAI format

### Authentication

The proxy supports two authentication modes:
- **Default API Key**: Set via `MAPLE_API_KEY` environment variable
- **Per-Request**: Clients provide `Authorization: Bearer <key>` header

For public deployments, avoid setting default API key to require per-request authentication.

## Configuration

Environment variables (can be set in .env file):
- `MAPLE_HOST` - Server bind address (default: 127.0.0.1)
- `MAPLE_PORT` - Server port (default: 8080)
- `MAPLE_BACKEND_URL` - OpenSecret backend URL (default: https://enclave.trymaple.ai)
- `MAPLE_API_KEY` - Default API key (optional)
- `MAPLE_DEBUG` - Enable debug logging
- `MAPLE_ENABLE_CORS` - Enable CORS for web clients
- `MAPLE_REQUEST_TIMEOUT_SECS` - Backend request timeout in seconds (default: 300)
- `MAPLE_STREAM_IDLE_TIMEOUT_SECS` - Streaming idle timeout in seconds (default: 300)

## Testing

Tests are located in `tests/` directory. Currently includes:
- `health_test.rs` - Tests for health check endpoints

Run tests with `just test` or `cargo test --locked`.

## Dependencies

Key dependencies:
- **opensecret** - Official OpenSecret SDK for TEE communication
- **axum** - Web framework for the HTTP server
- **tokio** - Async runtime
- **tower/tower-http** - Middleware for CORS and tracing
- **clap** - CLI argument parsing
- **dotenvy** - .env file support
Loading
Loading