Download tinfoil-proxy at runtime (build sandbox has no GitHub access)
This commit is contained in:
1 parent
26b0edc6a8
commit
8a54e75d4e
2 files changed
+14
-11
No files matched your search
+1
-10
@@ -6,16 +6,7 @@ FROM ghcr.io/berriai/litellm:main-v1.74.0-stable
|
|||||||
# volume-ownership issues.
|
# volume-ownership issues.
|
||||||
|
|
||||||
# Create the data directory (Cloudron mounts the localstorage volume here)
|
# Create the data directory (Cloudron mounts the localstorage volume here)
|
||||||
RUN mkdir -p /app/data
|
RUN mkdir -p /app/data /app/code
|
||||||
|
|
||||||
# Tinfoil proxy — a verified local proxy that encrypts request/response bodies
|
|
||||||
# with EHBP (HPKE) before forwarding to the Tinfoil enclave. LiteLLM's openai/
|
|
||||||
# provider sends plaintext, which Tinfoil rejects (426 EHBP_REQUIRED), so the
|
|
||||||
# proxy sits between LiteLLM and the enclave. Statically-linked Go binary,
|
|
||||||
# pinned to a specific release for reproducible builds. Downloaded with Python
|
|
||||||
# (guaranteed present in the Python base image) rather than curl/wget.
|
|
||||||
RUN python3 -c "import urllib.request; urllib.request.urlretrieve('https://github.com/tinfoilsh/tinfoil-proxy/releases/download/v0.2.3/tinfoil-proxy-linux-amd64', '/app/code/tinfoil-proxy')" \
|
|
||||||
&& chmod +x /app/code/tinfoil-proxy
|
|
||||||
|
|
||||||
# Create a startup script that configures LiteLLM with Cloudron addons
|
# Create a startup script that configures LiteLLM with Cloudron addons
|
||||||
COPY start.sh /app/code/start.sh
|
COPY start.sh /app/code/start.sh
|
||||||
|
|||||||
@@ -131,8 +131,20 @@ echo "Starting LiteLLM on port 4000..."
|
|||||||
# attestation and encrypts request/response bodies with EHBP (HPKE), so
|
# attestation and encrypts request/response bodies with EHBP (HPKE), so
|
||||||
# LiteLLM can talk plaintext OpenAI to it while the proxy handles the
|
# LiteLLM can talk plaintext OpenAI to it while the proxy handles the
|
||||||
# end-to-end encryption to the Tinfoil enclave.
|
# end-to-end encryption to the Tinfoil enclave.
|
||||||
|
#
|
||||||
|
# The proxy binary is downloaded at runtime into /app/data (persistent,
|
||||||
|
# writable) because Cloudron's build sandbox has no outbound network access to
|
||||||
|
# GitHub. The running container does, so we fetch it here on first start.
|
||||||
|
TINFOIL_PROXY_BIN="/app/data/tinfoil-proxy"
|
||||||
|
TINFOIL_PROXY_VERSION="v0.2.3"
|
||||||
|
if [ ! -f "$TINFOIL_PROXY_BIN" ]; then
|
||||||
|
echo "Downloading Tinfoil proxy ${TINFOIL_PROXY_VERSION}..."
|
||||||
|
python3 -c "import urllib.request; urllib.request.urlretrieve('https://github.com/tinfoilsh/tinfoil-proxy/releases/download/${TINFOIL_PROXY_VERSION}/tinfoil-proxy-linux-amd64', '${TINFOIL_PROXY_BIN}')"
|
||||||
|
chmod +x "$TINFOIL_PROXY_BIN"
|
||||||
|
fi
|
||||||
|
|
||||||
echo "Starting Tinfoil proxy on 127.0.0.1:3301..."
|
echo "Starting Tinfoil proxy on 127.0.0.1:3301..."
|
||||||
/app/code/tinfoil-proxy -b 127.0.0.1 -p 3301 &
|
"$TINFOIL_PROXY_BIN" -b 127.0.0.1 -p 3301 &
|
||||||
TINFOIL_PROXY_PID=$!
|
TINFOIL_PROXY_PID=$!
|
||||||
echo "Tinfoil proxy PID: $TINFOIL_PROXY_PID"
|
echo "Tinfoil proxy PID: $TINFOIL_PROXY_PID"
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user