Switch to Tinfoil (TEE): add tinfoil-proxy sidecar for EHBP encryption, point LiteLLM at local proxy
This commit is contained in:
1 parent
2ce5c66b9b
commit
e05fec0ca8
3 files changed
+35
-10
No files matched your search
@@ -126,4 +126,17 @@ fi
|
||||
|
||||
# --- Start LiteLLM ---
|
||||
echo "Starting LiteLLM on port 4000..."
|
||||
|
||||
# Start the Tinfoil proxy as a local sidecar. It verifies the enclave
|
||||
# attestation and encrypts request/response bodies with EHBP (HPKE), so
|
||||
# LiteLLM can talk plaintext OpenAI to it while the proxy handles the
|
||||
# end-to-end encryption to the Tinfoil enclave.
|
||||
echo "Starting Tinfoil proxy on 127.0.0.1:3301..."
|
||||
/app/code/tinfoil-proxy -b 127.0.0.1 -p 3301 &
|
||||
TINFOIL_PROXY_PID=$!
|
||||
echo "Tinfoil proxy PID: $TINFOIL_PROXY_PID"
|
||||
|
||||
# Give the proxy a moment to verify the enclave attestation
|
||||
sleep 3
|
||||
|
||||
exec litellm --config "$CONFIG_FILE" --port 4000 --host 0.0.0.0
|
||||
Reference in new issue
Block a user