Import maple-proxy into proxy/ with history - #851
Merged
Merged
Conversation
…cret 🚀 Features: - Full OpenAI API compatibility (works with any OpenAI client) - Real-time streaming chat completions with Server-Sent Events - Secure TEE integration via OpenSecret SDK - Flexible authentication (per-request or server default API keys) - CORS support for web applications - Comprehensive environment configuration - Production-ready with proper error handling 🔧 Tech Stack: - Rust + Axum for high-performance HTTP server - OpenSecret SDK for secure TEE communication - Full streaming support with proper SSE formatting - Thread-safe client handling with Arc<RwLock> 📋 Usage: Set MAPLE_API_KEY and point any OpenAI client to localhost:8080/v1 🤖 Generated with Claude Code (https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
- Lightweight OpenAI-compatible proxy for Maple/OpenSecret TEE infrastructure - Full compatibility with any OpenAI client (ChatGPT clients, Cursor, Continue, etc.) - Support for streaming chat completions via Server-Sent Events (SSE) - Configurable backend URLs for local/dev/prod environments - MAPLE_API_KEY authentication with proper priority handling - Thread-safe TEE client integration using OpenSecret SDK - Comprehensive development tooling (justfile, git hooks, CI/CD) - Health check endpoints and model listing - Full test coverage with axum-test v18 Co-Authored-By: Claude <noreply@anthropic.com>
The justfile now properly loads all environment variables from .env when using run-dev, run-local, or run-prod commands. Previously these commands would override the backend URL but lose other important settings like MAPLE_API_KEY. - Modified run-with-backend to source .env before running - Ensures API keys and other configs are preserved - Tested with streaming API calls successfully
- Switched from local path dependency to published crate - OpenSecret SDK 0.2.0 is now officially available on crates.io - Tested and verified working with streaming completions
- Add multi-stage Dockerfile with cargo-chef for optimized builds (~127MB image) - Add docker-compose.yml with production defaults and resource limits - Add Podman support for NixOS/Linux environments - Update justfile with comprehensive Docker/Podman commands - Add .dockerignore for efficient build context - Document Docker deployment with security best practices - Configure CORS enabled by default for containerized deployments - Implement non-root user execution for enhanced security - Add health checks for container monitoring 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
- Add GitHub Actions workflow for automated Docker builds on push - Configure multi-platform builds (linux/amd64, linux/arm64) - Auto-publish to ghcr.io/opensecretcloud/maple-proxy - Add GHCR commands to justfile for local development - Update README with pre-built image instructions - Document CI/CD vs local development workflow This will trigger automatic Docker image builds on every push to master! 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
- Remove Cargo.lock from .gitignore (required for binaries) - Ensures consistent dependency versions across all builds - Fixes Docker build failures in GitHub Actions Standard Rust practice: commit Cargo.lock for binaries, ignore for libraries
Fixes the dependency_check job in GitHub Actions by installing cargo-machete before attempting to use it
- Cache cargo-tarpaulin in CI workflow - Cache cargo-audit and cargo-machete in Security workflow - Significantly speeds up CI runs by avoiding tool reinstalls - Tools only reinstall when cache misses Note: actions-rust-lang/setup-rust-toolchain already includes built-in caching for Rust toolchain and dependencies
- Use native ARM64 runners for Docker builds (10x+ speedup) - Use native ARM64 runners for Linux binary builds - Remove 6 unused dependencies (bytes, eventsource-stream, hyper, reqwest, thiserror, uuid) - Add caching for cargo tools in CI workflows - Update release workflow to build on all pushes for testing - Split Docker builds into parallel native architecture builds This dramatically reduces build times: - Docker builds: ~20min → ~3-5min - Binary builds: Much faster native ARM compilation - Smaller dependency tree and faster compilation 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
The workflow was trying to push both tagged images and by-digest at the same time, causing a conflict. Now we: - Push by digest only during the build phase - Apply tags later in the merge-manifests job - Remove per-architecture tag suffixes since we're using digests
Docker registry names must be lowercase. Changed from OpenSecretCloud/maple-proxy to opensecretcloud/maple-proxy to fix the 'invalid reference format' error.
Ensures that if one platform build fails, the other continues. This makes the CI more resilient and helps with debugging platform-specific issues.
Currently only 13.93% coverage which doesn't justify the 3-minute build time. Job is preserved as comments with instructions to re-enable once we have better test coverage for: - src/main.rs (0% coverage) - src/config.rs (0% coverage) - src/proxy.rs (5% coverage) This reduces CI time from ~3 minutes to under 30 seconds.
Each platform (linux/amd64 and linux/arm64) now has its own cache scope to prevent cache conflicts when building in parallel. This should fix the issue where one platform's build would invalidate the other's cache, causing slower builds.
- Add Config builder methods for programmatic configuration (new(), with_api_key(), with_debug(), with_cors()) - Export OpenAIError types from lib.rs for library consumers - Add examples/library_usage.rs demonstrating how to embed the proxy - Update README with library installation and usage instructions - Maintain full backward compatibility with existing CLI/binary usage This allows users to embed Maple Proxy directly in their Rust applications while preserving all existing functionality for binary/Docker deployments. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
- Add repository and homepage URLs - Add keywords for better search visibility - Add categories for proper classification - Successfully published to crates.io as v0.1.0 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
- Reduced tokio features from "full" to only required features (net, rt-multi-thread, macros) - This reduces compilation time and binary size - Bumped version from 0.1.0 to 0.1.1 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
Bump sdk to 0.2.1
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
Updates tracing-subscriber from 0.3.19 to 0.3.20 to address RUSTSEC-2025-0055: logging user input may result in poisoning logs with ANSI escape sequences. Also updates related dependencies (matchers, nu-ansi-term) and removes unused transitive dependencies (overload, winapi). Note: serde_cbor unmaintained warning (RUSTSEC-2021-0127) comes from opensecret SDK dependency and will be addressed in a future SDK update. Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
Bump SDK to 0.2.2 (adds tool calling support)
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
The sha prefix was creating invalid tags like :-<hash> when {{branch}} is empty on tag events.
Changed to only enable sha tags on default branch pushes.
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
…ssue-permission-maple-proxy Allow scheduled security audits to open issues
…-maple-proxy chore: bump version to 0.1.11
…y-advisories-maple-proxy Patch anyhow soundness advisory
Forward OpenAI-compatible inference requests through the raw OpenSecret transport, preserve provider-specific request and response data, harden the HTTP trust boundary, and remove the legacy typed Rust API for the 0.2.0 release.
…rmissions-maple-proxy feat: add lossless inference proxy transport
…le-proxy Enforce environment-scoped PCR0 trust in maple-proxy
…-1-maple-proxy chore: bump maple-proxy to 0.3.1
…le-proxy security: block compromised Rust crates
…proxy ci: enforce locked dependency resolution
…roxy Security: enforce daily RustSec advisory checks
…-proxy security: enforce unsoundness advisories
chore: bump proxy to 0.3.2
Deploying maple with
|
| Latest commit: |
9df7e3c
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://7292556a.maple-ca8.pages.dev |
| Branch Preview URL: | https://codex-monorepo-next-maple.maple-ca8.pages.dev |
This was referenced Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
OpenSecretCloud/maple-proxyat exact commit7b89422cf2ac22a6829161f99f6a2cce14142a8cunderproxy/with unsquashed Git historyproxy/.github/workflowsfiles in a separate signed cleanup commit because nested workflows do not execute in MapleRelease invariant
This PR does not create or enable any proxy release flow. Follow-up release work must never create a separate maple-proxy GitHub Release: proxy artifacts will ship only as part of ordinary Maple app releases so GitHub
/releases/latestalways remains a valid Maple desktop release for pre-v3.3.8 clients.Import verification
7b89422cf2ac22a6829161f99f6a2cce14142a8cproxy/tree:7b610d90fa030e438c4a8f64df45bd481c010aff7b610d90fa030e438c4a8f64df45bd481c010affValidation
cargo fmt --checkcargo clippy --locked --all-targets -- -D warningscargo test --locked: 27 proxy tests passedUpstream backlog
Git history does not migrate GitHub metadata. The old repository currently has draft PR #48 and issues #51 and #8 open; they remain explicitly tracked for resolution/porting before the old repository is frozen.