Download tinfoil-proxy at runtime (build sandbox has no GitHub access)

This commit is contained in:
inference-bot committed 2026-09-09 13:23:53 -06:00
1 parent 26b0edc6a8
commit 8a54e75d4e
2 files changed
+14 -11

No files matched your search

+1 -10
View File
@@ -6,16 +6,7 @@ FROM ghcr.io/berriai/litellm:main-v1.74.0-stable
# volume-ownership issues.
# Create the data directory (Cloudron mounts the localstorage volume here)
RUN mkdir -p /app/data
# Tinfoil proxy — a verified local proxy that encrypts request/response bodies
# with EHBP (HPKE) before forwarding to the Tinfoil enclave. LiteLLM's openai/
# provider sends plaintext, which Tinfoil rejects (426 EHBP_REQUIRED), so the
# proxy sits between LiteLLM and the enclave. Statically-linked Go binary,
# pinned to a specific release for reproducible builds. Downloaded with Python
# (guaranteed present in the Python base image) rather than curl/wget.
RUN python3 -c "import urllib.request; urllib.request.urlretrieve('https://github.com/tinfoilsh/tinfoil-proxy/releases/download/v0.2.3/tinfoil-proxy-linux-amd64', '/app/code/tinfoil-proxy')" \
&& chmod +x /app/code/tinfoil-proxy
RUN mkdir -p /app/data /app/code
# Create a startup script that configures LiteLLM with Cloudron addons
COPY start.sh /app/code/start.sh