diff --git a/enterprise/aibridgeproxyd/README.md b/enterprise/aibridgeproxyd/README.md new file mode 100644 index 0000000000..3c65c9db21 --- /dev/null +++ b/enterprise/aibridgeproxyd/README.md @@ -0,0 +1,38 @@ +# AI Bridge Proxy + +A MITM (Man-in-the-Middle) proxy server for intercepting and decrypting HTTPS requests to AI providers. + +## Overview + +The AI Bridge Proxy intercepts HTTPS traffic, decrypts it using a configured CA certificate, and forwards requests to AI Bridge for processing. + +## Configuration + +### Certificate Setup + +Generate a CA key pair for MITM: + +#### 1. Generate a new private key + +```sh +openssl genrsa -out mitm.key 2048 +chmod 400 mitm.key +``` + +#### 2. Create a self-signed CA certificate + +```sh +openssl req -new -x509 -days 365 \ + -key mitm.key \ + -out mitm.crt \ + -subj "/CN=Coder AI Bridge Proxy CA" +``` + +### Configuration options + +| Environment Variable | Description | Default | +|------------------------------------|---------------------------------|---------| +| `CODER_AIBRIDGE_PROXY_ENABLED` | Enable the AI Bridge Proxy | `false` | +| `CODER_AIBRIDGE_PROXY_LISTEN_ADDR` | Address the proxy listens on | `:8888` | +| `CODER_AIBRIDGE_PROXY_CERT_FILE` | Path to the CA certificate file | - | +| `CODER_AIBRIDGE_PROXY_KEY_FILE` | Path to the CA private key file | - | diff --git a/enterprise/aibridgeproxyd/aibridgeproxyd.go b/enterprise/aibridgeproxyd/aibridgeproxyd.go index d70c7699e8..0f6c86637a 100644 --- a/enterprise/aibridgeproxyd/aibridgeproxyd.go +++ b/enterprise/aibridgeproxyd/aibridgeproxyd.go @@ -18,7 +18,7 @@ import ( // It is responsible for: // - intercepting HTTPS requests to AI providers // - decrypting requests using the configured CA certificate -// - forwarding requests to aibridge for processing +// - forwarding requests to aibridged for processing type Server struct { logger slog.Logger proxy *goproxy.ProxyHttpServer @@ -55,8 +55,7 @@ func New(ctx context.Context, logger slog.Logger, opts Options) (*Server, error) // Decrypt all HTTPS requests via MITM. Requests are forwarded to // the original destination without modification for now. - // TODO(ssncferreira): Route requests to aibridged - // will be implemented upstack. + // TODO(ssncferreira): Route requests to aibridged will be implemented upstack. // Related to https://github.com/coder/internal/issues/1181 proxy.OnRequest().HandleConnect(goproxy.AlwaysMitm) @@ -82,6 +81,16 @@ func New(ctx context.Context, logger slog.Logger, opts Options) (*Server, error) return srv, nil } +// Close gracefully shuts down the proxy server. +func (s *Server) Close() error { + if s.httpServer == nil { + return nil + } + ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second) + defer cancel() + return s.httpServer.Shutdown(ctx) +} + // loadMitmCertificate loads the CA certificate and key for MITM into goproxy. func loadMitmCertificate(certFile, keyFile string) error { tlsCert, err := tls.LoadX509KeyPair(certFile, keyFile) @@ -102,13 +111,3 @@ func loadMitmCertificate(certFile, keyFile string) error { return nil } - -// Close gracefully shuts down the proxy server. -func (s *Server) Close() error { - if s.httpServer == nil { - return nil - } - ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second) - defer cancel() - return s.httpServer.Shutdown(ctx) -}