Skip to content

Import maple-proxy into proxy/ with history - #851

Merged
AnthonyRonning merged 97 commits into
masterfrom
codex-monorepo-next-maple
Aug 26, 2026
Merged

AnthonyRonning merged 97 commits into
masterfrom
codex-monorepo-next-maple

Conversation

@AnthonyRonning

@AnthonyRonning AnthonyRonning commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • import OpenSecretCloud/maple-proxy at exact commit 7b89422cf2ac22a6829161f99f6a2cce14142a8c under proxy/ with unsquashed Git history
  • remove the five nested proxy/.github/workflows files in a separate signed cleanup commit because nested workflows do not execute in Maple
  • make no dependency, build-routing, publishing, deployment, or release changes

Release invariant

This PR does not create or enable any proxy release flow. Follow-up release work must never create a separate maple-proxy GitHub Release: proxy artifacts will ship only as part of ordinary Maple app releases so GitHub /releases/latest always remains a valid Maple desktop release for pre-v3.3.8 clients.

Import verification

  • subtree merge second parent: 7b89422cf2ac22a6829161f99f6a2cce14142a8c
  • imported proxy/ tree: 7b610d90fa030e438c4a8f64df45bd481c010aff
  • upstream tree at the captured commit: 7b610d90fa030e438c4a8f64df45bd481c010aff
  • both Maple-side commits are signed
  • current delta from the byte-identical import is only deletion of the five inert nested workflows

Validation

  • Maple pre-commit hook: production frontend build and 765 frontend tests
  • cargo fmt --check
  • cargo clippy --locked --all-targets -- -D warnings
  • cargo test --locked: 27 proxy tests passed

Upstream backlog

Git history does not migrate GitHub metadata. The old repository currently has draft PR #48 and issues #51 and #8 open; they remain explicitly tracked for resolution/porting before the old repository is frozen.

AnthonyRonning and others added 30 commits August 25, 2025 14:45
…cret

🚀 Features:
- Full OpenAI API compatibility (works with any OpenAI client)
- Real-time streaming chat completions with Server-Sent Events
- Secure TEE integration via OpenSecret SDK
- Flexible authentication (per-request or server default API keys)
- CORS support for web applications
- Comprehensive environment configuration
- Production-ready with proper error handling

🔧 Tech Stack:
- Rust + Axum for high-performance HTTP server
- OpenSecret SDK for secure TEE communication
- Full streaming support with proper SSE formatting
- Thread-safe client handling with Arc<RwLock>

📋 Usage:
Set MAPLE_API_KEY and point any OpenAI client to localhost:8080/v1

🤖 Generated with Claude Code (https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
- Lightweight OpenAI-compatible proxy for Maple/OpenSecret TEE infrastructure
- Full compatibility with any OpenAI client (ChatGPT clients, Cursor, Continue, etc.)
- Support for streaming chat completions via Server-Sent Events (SSE)
- Configurable backend URLs for local/dev/prod environments
- MAPLE_API_KEY authentication with proper priority handling
- Thread-safe TEE client integration using OpenSecret SDK
- Comprehensive development tooling (justfile, git hooks, CI/CD)
- Health check endpoints and model listing
- Full test coverage with axum-test v18

Co-Authored-By: Claude <noreply@anthropic.com>
The justfile now properly loads all environment variables from .env
when using run-dev, run-local, or run-prod commands. Previously these
commands would override the backend URL but lose other important
settings like MAPLE_API_KEY.

- Modified run-with-backend to source .env before running
- Ensures API keys and other configs are preserved
- Tested with streaming API calls successfully
- Switched from local path dependency to published crate
- OpenSecret SDK 0.2.0 is now officially available on crates.io
- Tested and verified working with streaming completions
- Add multi-stage Dockerfile with cargo-chef for optimized builds (~127MB image)
- Add docker-compose.yml with production defaults and resource limits
- Add Podman support for NixOS/Linux environments
- Update justfile with comprehensive Docker/Podman commands
- Add .dockerignore for efficient build context
- Document Docker deployment with security best practices
- Configure CORS enabled by default for containerized deployments
- Implement non-root user execution for enhanced security
- Add health checks for container monitoring

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
- Add GitHub Actions workflow for automated Docker builds on push
- Configure multi-platform builds (linux/amd64, linux/arm64)
- Auto-publish to ghcr.io/opensecretcloud/maple-proxy
- Add GHCR commands to justfile for local development
- Update README with pre-built image instructions
- Document CI/CD vs local development workflow

This will trigger automatic Docker image builds on every push to master!

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
- Remove Cargo.lock from .gitignore (required for binaries)
- Ensures consistent dependency versions across all builds
- Fixes Docker build failures in GitHub Actions

Standard Rust practice: commit Cargo.lock for binaries, ignore for libraries
Fixes the dependency_check job in GitHub Actions by installing
cargo-machete before attempting to use it
- Cache cargo-tarpaulin in CI workflow
- Cache cargo-audit and cargo-machete in Security workflow
- Significantly speeds up CI runs by avoiding tool reinstalls
- Tools only reinstall when cache misses

Note: actions-rust-lang/setup-rust-toolchain already includes
built-in caching for Rust toolchain and dependencies
- Use native ARM64 runners for Docker builds (10x+ speedup)
- Use native ARM64 runners for Linux binary builds
- Remove 6 unused dependencies (bytes, eventsource-stream, hyper, reqwest, thiserror, uuid)
- Add caching for cargo tools in CI workflows
- Update release workflow to build on all pushes for testing
- Split Docker builds into parallel native architecture builds

This dramatically reduces build times:
- Docker builds: ~20min → ~3-5min
- Binary builds: Much faster native ARM compilation
- Smaller dependency tree and faster compilation

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
The workflow was trying to push both tagged images and by-digest
at the same time, causing a conflict. Now we:
- Push by digest only during the build phase
- Apply tags later in the merge-manifests job
- Remove per-architecture tag suffixes since we're using digests
Docker registry names must be lowercase. Changed from
OpenSecretCloud/maple-proxy to opensecretcloud/maple-proxy
to fix the 'invalid reference format' error.
Ensures that if one platform build fails, the other continues.
This makes the CI more resilient and helps with debugging
platform-specific issues.
Currently only 13.93% coverage which doesn't justify the 3-minute
build time. Job is preserved as comments with instructions to
re-enable once we have better test coverage for:
- src/main.rs (0% coverage)
- src/config.rs (0% coverage)
- src/proxy.rs (5% coverage)

This reduces CI time from ~3 minutes to under 30 seconds.
Each platform (linux/amd64 and linux/arm64) now has its own
cache scope to prevent cache conflicts when building in parallel.
This should fix the issue where one platform's build would
invalidate the other's cache, causing slower builds.
- Add Config builder methods for programmatic configuration (new(), with_api_key(), with_debug(), with_cors())
- Export OpenAIError types from lib.rs for library consumers
- Add examples/library_usage.rs demonstrating how to embed the proxy
- Update README with library installation and usage instructions
- Maintain full backward compatibility with existing CLI/binary usage

This allows users to embed Maple Proxy directly in their Rust applications
while preserving all existing functionality for binary/Docker deployments.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
- Add repository and homepage URLs
- Add keywords for better search visibility
- Add categories for proper classification
- Successfully published to crates.io as v0.1.0

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
- Reduced tokio features from "full" to only required features (net, rt-multi-thread, macros)
- This reduces compilation time and binary size
- Bumped version from 0.1.0 to 0.1.1

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
Updates tracing-subscriber from 0.3.19 to 0.3.20 to address RUSTSEC-2025-0055:
logging user input may result in poisoning logs with ANSI escape sequences.

Also updates related dependencies (matchers, nu-ansi-term) and removes
unused transitive dependencies (overload, winapi).

Note: serde_cbor unmaintained warning (RUSTSEC-2021-0127) comes from
opensecret SDK dependency and will be addressed in a future SDK update.

Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
Bump SDK to 0.2.2 (adds tool calling support)
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
The sha prefix was creating invalid tags like :-<hash> when {{branch}} is empty on tag events.
Changed to only enable sha tags on default branch pushes.

Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
…ssue-permission-maple-proxy

Allow scheduled security audits to open issues
…-maple-proxy

chore: bump version to 0.1.11
…y-advisories-maple-proxy

Patch anyhow soundness advisory
Forward OpenAI-compatible inference requests through the raw OpenSecret transport, preserve provider-specific request and response data, harden the HTTP trust boundary, and remove the legacy typed Rust API for the 0.2.0 release.
…rmissions-maple-proxy

feat: add lossless inference proxy transport
…le-proxy

Enforce environment-scoped PCR0 trust in maple-proxy
…-1-maple-proxy

chore: bump maple-proxy to 0.3.1
…le-proxy

security: block compromised Rust crates
…proxy

ci: enforce locked dependency resolution
…roxy

Security: enforce daily RustSec advisory checks
…-proxy

security: enforce unsoundness advisories
git-subtree-dir: proxy
git-subtree-mainline: 586403f
git-subtree-split: 7b89422
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying maple with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9df7e3c
Status: ✅  Deploy successful!
Preview URL: https://7292556a.maple-ca8.pages.dev
Branch Preview URL: https://codex-monorepo-next-maple.maple-ca8.pages.dev

View logs

@AnthonyRonning
AnthonyRonning merged commit f9ca9f5 into master Aug 26, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant