Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# The proxy image builds from the repository root because it consumes the
# in-tree Rust SDK. Keep the context limited to the two runtime crates.
**
!.dockerignore
!proxy/
!proxy/Dockerfile
!proxy/Cargo.toml
!proxy/Cargo.lock
!proxy/src/
!proxy/src/**
!sdk/
!sdk/rust/
!sdk/rust/Cargo.toml
!sdk/rust/src/
!sdk/rust/src/**
!sdk/rust/assets/
!sdk/rust/assets/**
12 changes: 9 additions & 3 deletions .github/workflows/proxy-container.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,19 +8,25 @@ on:
branches: [master]
paths:
- ".github/workflows/proxy-container.yml"
- "proxy/.dockerignore"
- ".dockerignore"
- "proxy/Dockerfile"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "proxy/src/**"
- "sdk/rust/Cargo.toml"
- "sdk/rust/src/**"
- "sdk/rust/assets/**"
pull_request:
paths:
- ".github/workflows/proxy-container.yml"
- "proxy/.dockerignore"
- ".dockerignore"
- "proxy/Dockerfile"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "proxy/src/**"
- "sdk/rust/Cargo.toml"
- "sdk/rust/src/**"
- "sdk/rust/assets/**"

jobs:
proxy-container:
Expand All @@ -45,7 +51,7 @@ jobs:
- name: Build proxy container without publishing
uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # was v5
with:
context: proxy
context: .
file: proxy/Dockerfile
platforms: ${{ matrix.platform }}
cache-from: type=gha,scope=proxy-${{ matrix.platform }}
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/proxy-rust.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@ on:
- "proxy/src/**"
- "proxy/tests/**"
- "proxy/examples/**"
- "sdk/rust/Cargo.toml"
- "sdk/rust/src/**"
- "sdk/rust/assets/**"
pull_request:
paths:
- ".github/workflows/proxy-rust.yml"
Expand All @@ -31,6 +34,9 @@ on:
- "proxy/src/**"
- "proxy/tests/**"
- "proxy/examples/**"
- "sdk/rust/Cargo.toml"
- "sdk/rust/src/**"
- "sdk/rust/assets/**"

env:
CARGO_TERM_COLOR: always
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/proxy-supply-chain.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,15 @@ on:
- "proxy/deny.toml"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "sdk/rust/Cargo.toml"
push:
branches: [master]
paths:
- ".github/workflows/proxy-supply-chain.yml"
- "proxy/deny.toml"
- "proxy/Cargo.toml"
- "proxy/Cargo.lock"
- "sdk/rust/Cargo.toml"
schedule:
- cron: "29 7 * * *"
workflow_dispatch:
Expand Down
16 changes: 15 additions & 1 deletion .github/workflows/rust-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,17 +9,29 @@ on:
paths:
- ".github/workflows/rust-tests.yml"
- "frontend/src-tauri/**"
- "proxy/Cargo.toml"
- "proxy/src/**"
- "sdk/rust/Cargo.toml"
- "sdk/rust/src/**"
- "sdk/rust/assets/**"
- "scripts/ci/_common.sh"
- "scripts/ci/rust.sh"
- "scripts/ci/verify-local-rust-deps.sh"
- "flake.nix"
- "flake.lock"
pull_request:
branches: [master]
paths:
- ".github/workflows/rust-tests.yml"
- "frontend/src-tauri/**"
- "proxy/Cargo.toml"
- "proxy/src/**"
- "sdk/rust/Cargo.toml"
- "sdk/rust/src/**"
- "sdk/rust/assets/**"
- "scripts/ci/_common.sh"
- "scripts/ci/rust.sh"
- "scripts/ci/verify-local-rust-deps.sh"
- "flake.nix"
- "flake.lock"

Expand All @@ -46,7 +58,9 @@ jobs:
${{ runner.os }}-sccache-

- name: Run Rust unit tests
run: nix develop --no-update-lock-file .#ci -c ./scripts/ci/rust.sh
run: |
nix develop --no-update-lock-file .#ci -c ./scripts/ci/verify-local-rust-deps.sh
nix develop --no-update-lock-file .#ci -c ./scripts/ci/rust.sh

- name: Show sccache stats
if: always()
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/supply-chain.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,17 @@ on:
- "deny.toml"
- "frontend/src-tauri/Cargo.toml"
- "frontend/src-tauri/Cargo.lock"
- "proxy/Cargo.toml"
- "sdk/rust/Cargo.toml"
push:
branches: [master]
paths:
- ".github/workflows/supply-chain.yml"
- "deny.toml"
- "frontend/src-tauri/Cargo.toml"
- "frontend/src-tauri/Cargo.lock"
- "proxy/Cargo.toml"
- "sdk/rust/Cargo.toml"
schedule:
- cron: "41 6 * * *"
workflow_dispatch:
Expand Down
19 changes: 8 additions & 11 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,21 +44,18 @@ OpenSecret is its required backend. Keep these runtime paths distinct:
- Local proxy: a separate user-facing OpenAI-compatible relay. Research chat
and Agent Mode do not internally route through it.

The OpenSecret SDK source lives under `sdk/`. Treat `frontend/package.json` as
the authority for whether the browser client consumes a published version or
the in-tree `file:../sdk` package. Native Agent Mode continues to consume the
published Rust crate pinned in `frontend/src-tauri/Cargo.toml` until the proxy
and Rust consumers switch together. Do not assume the TypeScript and Rust SDKs
have identical transports, retries, or API coverage. A backend contract change
that Maple consumes needs compatibility checks for every affected client path.
The OpenSecret SDK source lives under `sdk/`. The browser client consumes the
in-tree `file:../sdk` package, and the desktop Tauri app plus proxy consume the
in-tree `sdk/rust` crate. Do not assume the TypeScript and Rust SDKs have
identical transports, retries, or API coverage. A backend contract change that
Maple consumes needs compatibility checks for every affected client path.

The standalone proxy source lives under `proxy/`. From the repository root,
run its Rust commands through
`nix develop --no-update-lock-file ./proxy -c bash -lc 'cd proxy && ...'`;
root path-scoped workflows own proxy CI. Until the coordinated Rust dependency
switch lands, the Tauri app and proxy continue to consume their published
crate dependencies, so a proxy-only source change is not yet an application
build input.
root path-scoped workflows own proxy CI. Proxy and Rust SDK runtime changes are
desktop application build inputs; container, test, documentation, and
standalone lockfile changes remain independent.

## Code ownership and placement

Expand Down
7 changes: 3 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,9 @@ Agent Mode embeds Goose and uses the Rust OpenSecret SDK through Tauri. The
local OpenAI-compatible proxy is a separate user-facing service.

The OpenSecret SDK source and its upstream Git history live under
[`sdk/`](sdk/README.md), and Maple's TypeScript client consumes that in-tree
package. The proxy source and its upstream history live under
[`proxy/`](proxy/README.md). Native Maple and the proxy still consume published
Rust crates until their local references switch together.
[`sdk/`](sdk/README.md), and Maple consumes its in-tree TypeScript and Rust
packages. The proxy source and its upstream history live under
[`proxy/`](proxy/README.md); desktop Maple consumes that in-tree crate too.

## Quick start

Expand Down
6 changes: 1 addition & 5 deletions frontend/src-tauri/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

8 changes: 4 additions & 4 deletions frontend/src-tauri/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -36,11 +36,8 @@ tauri-plugin-os = "2.3.2"
tauri-plugin-sign-in-with-apple = "1.0.2"
tokio = { version = "1.0", features = ["io-std", "io-util", "net", "process", "sync", "rt-multi-thread", "macros", "time"] }
once_cell = "1.18.0"
maple-proxy = "0.3.2"
tauri-plugin-fs = "2.5.1"
anyhow = "1.0"
axum = "0.8"
tower-http = { version = "0.6", features = ["cors"] }
pdf_oxide = { version = "=0.3.74", git = "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/OpenSecretCloud/pdf_oxide.git", rev = "f24b43ba997dd91ce60839640a8ce3ac92a87a5d", features = ["ocr-ort", "rendering"] }
# Keep the pre-1.0 Word parser exact-pinned. office_oxide is already in the
# PDFOxide graph; Maple adds strict DOC/DOCX container and semantic guards.
Expand All @@ -66,7 +63,10 @@ ort = { version = "=2.0.0-rc.11", default-features = false, features = ["std", "
# history.
goose = { git = "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/aaif-goose/goose.git", rev = "f9c7aaccde4834810dfd13d5efa8f0d39ba28a20", package = "goose", default-features = false }
goose-providers = { git = "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/aaif-goose/goose.git", rev = "f9c7aaccde4834810dfd13d5efa8f0d39ba28a20", package = "goose-providers", default-features = false }
opensecret = "3.6.2"
maple-proxy = { version = "0.3.3", path = "../../proxy" }
opensecret = { version = "3.6.2", path = "../../sdk/rust" }
axum = "0.8"
tower-http = { version = "0.6", features = ["cors"] }
rand = "0.8.6"
async-trait = "0.1"
rmcp = { version = "=3.1.2", default-features = false, features = ["client", "transport-streamable-http-client-reqwest"] }
Expand Down
2 changes: 2 additions & 0 deletions frontend/src-tauri/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,11 @@ mod legacy_tts_cleanup;
#[cfg(desktop)]
mod maple_api;
mod onnxruntime;
#[cfg(desktop)]
mod open_secret_config;
mod pdf_extractor;
mod pdf_ocr;
#[cfg(desktop)]
mod proxy;
#[cfg(desktop)]
mod updater_preferences;
Expand Down
55 changes: 0 additions & 55 deletions proxy/.dockerignore

This file was deleted.

4 changes: 1 addition & 3 deletions proxy/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions proxy/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "maple-proxy"
version = "0.3.2"
version = "0.3.3"
edition = "2021"
authors = ["OpenSecret"]
description = "Lightweight OpenAI-compatible proxy server for Maple/OpenSecret TEE infrastructure"
Expand Down Expand Up @@ -29,7 +29,7 @@ path = "src/main.rs"

[dependencies]
# OpenSecret SDK
opensecret = "3.6.2"
opensecret = { version = "3.6.2", path = "../sdk/rust" }

# Web server
axum = { version = "0.8.4", features = ["http2", "macros"] }
Expand Down
28 changes: 9 additions & 19 deletions proxy/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,29 +1,20 @@
# Build stage with cargo-chef for dependency caching
FROM docker.io/lukemathwalker/cargo-chef:latest-rust-1 AS chef
# Build the proxy and its in-tree Rust SDK dependency together.
FROM docker.io/library/rust:1.89.0-bookworm AS builder
WORKDIR /app

# Plan stage - prepare dependency list for caching
FROM chef AS planner
COPY Cargo.toml Cargo.lock ./
COPY src ./src
RUN cargo chef prepare --recipe-path recipe.json

# Build stage - build dependencies separately for caching
FROM chef AS builder

# Install build dependencies
RUN apt-get update && apt-get install -y \
pkg-config \
libssl-dev \
&& rm -rf /var/lib/apt/lists/*

# Copy and build dependencies (cached if unchanged)
COPY --from=planner /app/recipe.json recipe.json
RUN cargo chef cook --locked --release --recipe-path recipe.json

# Copy source code and build the application
COPY Cargo.toml Cargo.lock ./
COPY src ./src
COPY proxy/Cargo.toml proxy/Cargo.lock ./proxy/
COPY proxy/src ./proxy/src
COPY sdk/rust/Cargo.toml ./sdk/rust/
COPY sdk/rust/src ./sdk/rust/src
COPY sdk/rust/assets ./sdk/rust/assets
WORKDIR /app/proxy
RUN cargo build --locked --release --bin maple-proxy

# Runtime stage - minimal image for production
Expand All @@ -42,7 +33,7 @@ RUN useradd -m -u 1001 -s /bin/bash maple
WORKDIR /app

# Copy the binary from builder
COPY --from=builder /app/target/release/maple-proxy /usr/local/bin/maple-proxy
COPY --from=builder /app/proxy/target/release/maple-proxy /usr/local/bin/maple-proxy

# Set ownership
RUN chown -R maple:maple /app
Expand All @@ -64,7 +55,6 @@ ENV MAPLE_HOST=0.0.0.0 \
# Expose the port
EXPOSE 8080

# Health check
# Health check (curl needs to be installed)
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD curl -f http://localhost:8080/health || exit 1
Expand Down
Loading
Loading