feat: add TLS listener support to aibridgeproxyd (#22411)

## Description

Adds optional TLS support for the AI Bridge Proxy listener. When TLS cert and key files are provided, the proxy serves over HTTPS instead of plain HTTP.

## Changes

* New configuration options to enable TLS on the proxy listener 
* Wraps the TCP listener in `tls.NewListener` when configured
* Tests for validation errors, invalid files, and full integration (tunneled + MITM) through a TLS listener

Note: Documentation for TLS listener setup and client configuration will be handled in a follow-up PR.
Related to: https://github.com/coder/internal/issues/1335
This commit is contained in:
Susana Ferreira
2026-03-05 09:19:34 +00:00
committed by GitHub
parent 7bcd9f6de8
commit 21c91cebaa
13 changed files with 346 additions and 7 deletions
+22
View File
@@ -3857,6 +3857,26 @@ Write out the current server config as YAML to stdout.`,
Group: &deploymentGroupAIBridgeProxy,
YAML: "listen_addr",
},
{
Name: "AI Bridge Proxy TLS Certificate File",
Description: "Path to the TLS certificate file for the AI Bridge Proxy listener. Must be set together with AI Bridge Proxy TLS Key File.",
Flag: "aibridge-proxy-tls-cert-file",
Env: "CODER_AIBRIDGE_PROXY_TLS_CERT_FILE",
Value: &c.AI.BridgeProxyConfig.TLSCertFile,
Default: "",
Group: &deploymentGroupAIBridgeProxy,
YAML: "tls_cert_file",
},
{
Name: "AI Bridge Proxy TLS Key File",
Description: "Path to the TLS private key file for the AI Bridge Proxy listener. Must be set together with AI Bridge Proxy TLS Certificate File.",
Flag: "aibridge-proxy-tls-key-file",
Env: "CODER_AIBRIDGE_PROXY_TLS_KEY_FILE",
Value: &c.AI.BridgeProxyConfig.TLSKeyFile,
Default: "",
Group: &deploymentGroupAIBridgeProxy,
YAML: "tls_key_file",
},
{
Name: "AI Bridge Proxy MITM CA Certificate File",
Description: "Path to the CA certificate file used to intercept (MITM) HTTPS traffic from AI clients. This CA must be trusted by AI clients for the proxy to decrypt their requests.",
@@ -4014,6 +4034,8 @@ type AIBridgeBedrockConfig struct {
type AIBridgeProxyConfig struct {
Enabled serpent.Bool `json:"enabled" typescript:",notnull"`
ListenAddr serpent.String `json:"listen_addr" typescript:",notnull"`
TLSCertFile serpent.String `json:"tls_cert_file" typescript:",notnull"`
TLSKeyFile serpent.String `json:"tls_key_file" typescript:",notnull"`
MITMCertFile serpent.String `json:"cert_file" typescript:",notnull"`
MITMKeyFile serpent.String `json:"key_file" typescript:",notnull"`
DomainAllowlist serpent.StringArray `json:"domain_allowlist" typescript:",notnull"`