Switch to Tinfoil (TEE): add tinfoil-proxy sidecar for EHBP encryption, point LiteLLM at local proxy
This commit is contained in:
1 parent
2ce5c66b9b
commit
e05fec0ca8
3 files changed
+35
-10
No files matched your search
+10
@@ -8,6 +8,16 @@ FROM ghcr.io/berriai/litellm:main-v1.74.0-stable
|
||||
# Create the data directory (Cloudron mounts the localstorage volume here)
|
||||
RUN mkdir -p /app/data
|
||||
|
||||
# Tinfoil proxy — a verified local proxy that encrypts request/response bodies
|
||||
# with EHBP (HPKE) before forwarding to the Tinfoil enclave. LiteLLM's openai/
|
||||
# provider sends plaintext, which Tinfoil rejects (426 EHBP_REQUIRED), so the
|
||||
# proxy sits between LiteLLM and the enclave. Statically-linked Go binary,
|
||||
# pinned to a specific release for reproducible builds. Downloaded with Python
|
||||
# (guaranteed present in the Python base image) rather than curl/wget.
|
||||
ARG TINFOIL_PROXY_VERSION=v0.2.3
|
||||
RUN python3 -c "import urllib.request; urllib.request.urlretrieve('https://github.com/tinfoilsh/tinfoil-proxy/releases/download/${TINFOIL_PROXY_VERSION}/tinfoil-proxy-linux-amd64', '/app/code/tinfoil-proxy')" \
|
||||
&& chmod +x /app/code/tinfoil-proxy
|
||||
|
||||
# Create a startup script that configures LiteLLM with Cloudron addons
|
||||
COPY start.sh /app/code/start.sh
|
||||
RUN chmod +x /app/code/start.sh
|
||||
|
||||
Reference in new issue
Block a user