feat: add core AI MITM proxy daemon (#21296)

## Description

Adds the core AI Bridge MITM proxy daemon. This proxy intercepts HTTPS traffic, decrypts it using a configured CA certificate, and forwards requests to AIBridge for processing.

## Changes

* Added `aibridgeproxyd` package with the core proxy server implementation
* Added configuration options: `CODER_AIBRIDGE_PROXY_ENABLED`, `CODER_AIBRIDGE_PROXY_LISTEN_ADDR`, `CODER_AIBRIDGE_PROXY_CERT_FILE`, `CODER_AIBRIDGE_PROXY_KEY_FILE`
* Added tests for server initialization and MITM functionality

Closes https://github.com/coder/internal/issues/1180
This commit is contained in:
Susana Ferreira
2025-12-29 15:31:51 +00:00
committed by GitHub
parent 5655760f1d
commit b97572285a
16 changed files with 665 additions and 4 deletions
+6
View File
@@ -162,6 +162,12 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
},
"agent_stat_refresh_interval": 0,
"ai": {
"aibridge_proxy": {
"cert_file": "string",
"enabled": true,
"key_file": "string",
"listen_addr": "string"
},
"bridge": {
"anthropic": {
"base_url": "string",
+42 -3
View File
@@ -592,6 +592,26 @@
| `base_url` | string | false | | |
| `key` | string | false | | |
## codersdk.AIBridgeProxyConfig
```json
{
"cert_file": "string",
"enabled": true,
"key_file": "string",
"listen_addr": "string"
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
|---------------|---------|----------|--------------|-------------|
| `cert_file` | string | false | | |
| `enabled` | boolean | false | | |
| `key_file` | string | false | | |
| `listen_addr` | string | false | | |
## codersdk.AIBridgeTokenUsage
```json
@@ -690,6 +710,12 @@
```json
{
"aibridge_proxy": {
"cert_file": "string",
"enabled": true,
"key_file": "string",
"listen_addr": "string"
},
"bridge": {
"anthropic": {
"base_url": "string",
@@ -717,9 +743,10 @@
### Properties
| Name | Type | Required | Restrictions | Description |
|----------|----------------------------------------------------|----------|--------------|-------------|
| `bridge` | [codersdk.AIBridgeConfig](#codersdkaibridgeconfig) | false | | |
| Name | Type | Required | Restrictions | Description |
|------------------|--------------------------------------------------------------|----------|--------------|-------------|
| `aibridge_proxy` | [codersdk.AIBridgeProxyConfig](#codersdkaibridgeproxyconfig) | false | | |
| `bridge` | [codersdk.AIBridgeConfig](#codersdkaibridgeconfig) | false | | |
## codersdk.APIAllowListTarget
@@ -2595,6 +2622,12 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
},
"agent_stat_refresh_interval": 0,
"ai": {
"aibridge_proxy": {
"cert_file": "string",
"enabled": true,
"key_file": "string",
"listen_addr": "string"
},
"bridge": {
"anthropic": {
"base_url": "string",
@@ -3126,6 +3159,12 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
},
"agent_stat_refresh_interval": 0,
"ai": {
"aibridge_proxy": {
"cert_file": "string",
"enabled": true,
"key_file": "string",
"listen_addr": "string"
},
"bridge": {
"anthropic": {
"base_url": "string",
+42
View File
@@ -1814,6 +1814,48 @@ Maximum number of concurrent AI Bridge requests per replica. Set to 0 to disable
Maximum number of AI Bridge requests per second per replica. Set to 0 to disable (unlimited).
### --aibridge-proxy-enabled
| | |
|-------------|--------------------------------------------|
| Type | <code>bool</code> |
| Environment | <code>$CODER_AIBRIDGE_PROXY_ENABLED</code> |
| YAML | <code>aibridgeproxy.enabled</code> |
| Default | <code>false</code> |
Enable the AI Bridge MITM Proxy for intercepting and decrypting AI provider requests.
### --aibridge-proxy-listen-addr
| | |
|-------------|------------------------------------------------|
| Type | <code>string</code> |
| Environment | <code>$CODER_AIBRIDGE_PROXY_LISTEN_ADDR</code> |
| YAML | <code>aibridgeproxy.listen_addr</code> |
| Default | <code>:8888</code> |
The address the AI Bridge Proxy will listen on.
### --aibridge-proxy-cert-file
| | |
|-------------|----------------------------------------------|
| Type | <code>string</code> |
| Environment | <code>$CODER_AIBRIDGE_PROXY_CERT_FILE</code> |
| YAML | <code>aibridgeproxy.cert_file</code> |
Path to the CA certificate file for AI Bridge Proxy.
### --aibridge-proxy-key-file
| | |
|-------------|---------------------------------------------|
| Type | <code>string</code> |
| Environment | <code>$CODER_AIBRIDGE_PROXY_KEY_FILE</code> |
| YAML | <code>aibridgeproxy.key_file</code> |
Path to the CA private key file for AI Bridge Proxy.
### --audit-logs-retention
| | |