Skip to content

feat(testcontainers): outbound TLS trust (upstreamTrust) on RiftContainer - #249

Merged
EtaCassiopeia merged 1 commit into
masterfrom
feat/rift-248-container-upstream-trust
Sep 23, 2026
Merged

EtaCassiopeia merged 1 commit into
masterfrom
feat/rift-248-container-upstream-trust

Conversation

@EtaCassiopeia

Copy link
Copy Markdown
Collaborator

RiftContainer.withUpstreamTrust(UpstreamTrust) brings outbound TLS trust to the testcontainers transport. CaFile and inline CaPem are copied into the container and named to the engine through RIFT_UPSTREAM_CA_FILE. SkipVerify sets RIFT_UPSTREAM_TLS_SKIP_VERIFY and logs the same development-only warning as the other transports.
An image tag that is a version older than 0.18.0 is refused up front, through a gate now shared with SpawnOptions (UpstreamTrust.MIN_ENGINE_VERSION / supportedBy). A new live RiftContainerUpstreamTrustIT mirrors UpstreamTrustIT: with no trust the private-CA origin is refused, and with CaFile, CaPem or SkipVerify it is reached.

Closes #248

🤖 Generated with Claude Code

…iner

UpstreamTrust reached the embedded and spawn transports in 0.3.0, but a
RiftContainer user had no way to make a proxy stub (or the intercept
listener's origin leg) trust an HTTPS origin behind a private CA, so the
container transport could not record such an origin at all.

withUpstreamTrust takes all three variants. The engine already reads its
trust flags from the environment (RIFT_UPSTREAM_CA_FILE /
RIFT_UPSTREAM_TLS_SKIP_VERIFY), which is how the container already
passes MB_APIKEY and RIFT_INTERCEPT_PORT, so no command override is
needed. CaFile and CaPem are both written into the container, which is
why a container, unlike spawn, can take an inline PEM. SkipVerify logs
the same development-only warning as the other transports.

The policy is applied in configure(), at start: a replaced policy
leaves nothing behind, and a CaFile is read when the engine starts, as
elsewhere. An image tag that is a version older than 0.18.0 is refused
up front, sharing the gate with SpawnOptions through
UpstreamTrust.MIN_ENGINE_VERSION / supportedBy.

Closes #248
@EtaCassiopeia
EtaCassiopeia merged commit c0e5693 into master Sep 23, 2026
18 checks passed
@EtaCassiopeia
EtaCassiopeia deleted the feat/rift-248-container-upstream-trust branch September 23, 2026 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RiftContainer: no way to set outbound TLS trust (upstreamTrust) for proxy stubs

1 participant