Download tinfoil-proxy at runtime (build sandbox has no GitHub access)

This commit is contained in:
inference-bot committed 2026-09-09 13:23:53 -06:00
1 parent 26b0edc6a8
commit 8a54e75d4e
2 files changed
+14 -11

No files matched your search

+13 -1
View File
@@ -131,8 +131,20 @@ echo "Starting LiteLLM on port 4000..."
# attestation and encrypts request/response bodies with EHBP (HPKE), so
# LiteLLM can talk plaintext OpenAI to it while the proxy handles the
# end-to-end encryption to the Tinfoil enclave.
#
# The proxy binary is downloaded at runtime into /app/data (persistent,
# writable) because Cloudron's build sandbox has no outbound network access to
# GitHub. The running container does, so we fetch it here on first start.
TINFOIL_PROXY_BIN="/app/data/tinfoil-proxy"
TINFOIL_PROXY_VERSION="v0.2.3"
if [ ! -f "$TINFOIL_PROXY_BIN" ]; then
echo "Downloading Tinfoil proxy ${TINFOIL_PROXY_VERSION}..."
python3 -c "import urllib.request; urllib.request.urlretrieve('https://github.com/tinfoilsh/tinfoil-proxy/releases/download/${TINFOIL_PROXY_VERSION}/tinfoil-proxy-linux-amd64', '${TINFOIL_PROXY_BIN}')"
chmod +x "$TINFOIL_PROXY_BIN"
fi
echo "Starting Tinfoil proxy on 127.0.0.1:3301..."
/app/code/tinfoil-proxy -b 127.0.0.1 -p 3301 &
"$TINFOIL_PROXY_BIN" -b 127.0.0.1 -p 3301 &
TINFOIL_PROXY_PID=$!
echo "Tinfoil proxy PID: $TINFOIL_PROXY_PID"