Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
/.github/CODEOWNERS @AnthonyRonning
/.github/workflows/ @AnthonyRonning
/updates/ @AnthonyRonning
/proxy/ @AnthonyRonning
53 changes: 53 additions & 0 deletions .github/workflows/proxy-container.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
name: Proxy container CI

permissions:
contents: read

on:
push:
branches: [master]
paths:
- ".github/workflows/proxy-container.yml"
- "proxy/.dockerignore"
- "proxy/Dockerfile"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "proxy/src/**"
pull_request:
paths:
- ".github/workflows/proxy-container.yml"
- "proxy/.dockerignore"
- "proxy/Dockerfile"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "proxy/src/**"

jobs:
proxy-container:
strategy:
fail-fast: false
matrix:
include:
- platform: linux/amd64
runner: ubuntu-latest
- platform: linux/arm64
runner: ubuntu-24.04-arm
runs-on: ${{ matrix.runner }}
timeout-minutes: 30
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # was v4
with:
persist-credentials: false

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # was v3

- name: Build proxy container without publishing
uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # was v5
with:
context: proxy
file: proxy/Dockerfile
platforms: ${{ matrix.platform }}
cache-from: type=gha,scope=proxy-${{ matrix.platform }}
cache-to: type=gha,mode=max,scope=proxy-${{ matrix.platform }}
push: false
69 changes: 69 additions & 0 deletions .github/workflows/proxy-rust.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
name: Proxy Rust CI

permissions:
contents: read

on:
push:
branches: [master]
paths:
- ".github/workflows/proxy-rust.yml"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "proxy/clippy.toml"
- "proxy/flake.nix"
- "proxy/flake.lock"
- "proxy/rust-toolchain.toml"
- "proxy/rustfmt.toml"
- "proxy/src/**"
- "proxy/tests/**"
- "proxy/examples/**"
pull_request:
paths:
- ".github/workflows/proxy-rust.yml"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "proxy/clippy.toml"
- "proxy/flake.nix"
- "proxy/flake.lock"
- "proxy/rust-toolchain.toml"
- "proxy/rustfmt.toml"
- "proxy/src/**"
- "proxy/tests/**"
- "proxy/examples/**"

env:
CARGO_TERM_COLOR: always
RUSTFLAGS: "-D warnings"

jobs:
proxy-rust:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # was v4
with:
persist-credentials: false

- name: Install Nix
uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # was v22
with:
github-token: ""

- name: Cache Rust dependencies
uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # was v2
with:
workspaces: proxy -> target
add-rust-environment-hash-key: "false"
key: ${{ hashFiles('proxy/Cargo.lock', 'proxy/rust-toolchain.toml', 'proxy/flake.lock') }}

- name: Run credential-free proxy checks
run: |
nix develop --no-update-lock-file ./proxy -c bash -lc '
cd proxy
cargo fmt --all -- --check
cargo clippy --locked --all-targets --all-features -- -D warnings
cargo test --locked --all-features
RUSTDOCFLAGS="-D warnings" cargo doc --locked --no-deps --all-features
cargo machete
'
40 changes: 40 additions & 0 deletions .github/workflows/proxy-supply-chain.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: Proxy Rust supply-chain checks

on:
pull_request:
paths:
- ".github/workflows/proxy-supply-chain.yml"
- "proxy/deny.toml"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
push:
branches: [master]
paths:
- ".github/workflows/proxy-supply-chain.yml"
- "proxy/deny.toml"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
schedule:
- cron: "29 7 * * *"
workflow_dispatch:

permissions:
contents: read

jobs:
proxy-cargo-deny:
name: Proxy RustSec advisories and malicious crates
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # was v4
with:
persist-credentials: false

- name: Check proxy RustSec advisories and incident denylist
uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # was v2
with:
manifest-path: proxy/Cargo.toml
command: check advisories bans
arguments: --config proxy/deny.toml --all-features --locked
8 changes: 8 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,14 @@ and Rust consumers switch together. Do not assume the TypeScript and Rust SDKs
have identical transports, retries, or API coverage. A backend contract change
that Maple consumes needs compatibility checks for every affected client path.

The standalone proxy source lives under `proxy/`. From the repository root,
run its Rust commands through
`nix develop --no-update-lock-file ./proxy -c bash -lc 'cd proxy && ...'`;
root path-scoped workflows own proxy CI. Until the coordinated Rust dependency
switch lands, the Tauri app and proxy continue to consume their published
crate dependencies, so a proxy-only source change is not yet an application
build input.

## Code ownership and placement

- `frontend/src/routes`, `components`, `contexts`, and `state` own routing,
Expand Down
9 changes: 5 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,10 +10,11 @@ uses the TypeScript OpenSecret SDK with the Responses and Conversations APIs;
Agent Mode embeds Goose and uses the Rust OpenSecret SDK through Tauri. The
local OpenAI-compatible proxy is a separate user-facing service.

The OpenSecret SDK source and its upstream Git history are imported under
[`sdk/`](sdk/README.md). Maple still consumes the published TypeScript and Rust
SDK packages until follow-up changes explicitly switch those dependencies to
the in-repository source.
The OpenSecret SDK source and its upstream Git history live under
[`sdk/`](sdk/README.md), and Maple's TypeScript client consumes that in-tree
package. The proxy source and its upstream history live under
[`proxy/`](proxy/README.md). Native Maple and the proxy still consume published
Rust crates until their local references switch together.

## Quick start

Expand Down
68 changes: 0 additions & 68 deletions proxy/.githooks/pre-commit

This file was deleted.

101 changes: 0 additions & 101 deletions proxy/CLAUDE.md

This file was deleted.

4 changes: 2 additions & 2 deletions proxy/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@ edition = "2021"
authors = ["OpenSecret"]
description = "Lightweight OpenAI-compatible proxy server for Maple/OpenSecret TEE infrastructure"
license = "MIT"
repository = "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/OpenSecretCloud/maple-proxy"
homepage = "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/OpenSecretCloud/maple-proxy"
repository = "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/OpenSecretCloud/Maple"
homepage = "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/OpenSecretCloud/Maple/tree/master/proxy"
keywords = ["openai", "proxy", "tee", "opensecret", "maple"]
categories = ["web-programming::http-server", "api-bindings"]
include = [
Expand Down
Loading
Loading