Repository navigation
feat: tunnel to apps, not just databases - #15
Draft
jeroenrinzema wants to merge 1 commit into
Draft
jeroenrinzema wants to merge 1 commit into
jeroenrinzema wants to merge 1 commit into
Conversation
The broker now targets any resource that listens on a TCP port, so the CLI stops assuming a database. OpenSessionRequest.database_id became resource_id (field 1, same number and type) and gained a port; the response carries target_kind and the resolved remote port. A new Target enum replaces the bare DatabaseEngine that used to thread through the proxy, the banner and the DSN table. An app target has no managed credentials, so the credential preflight is skipped for it rather than failing on a missing password, and the banner drops the credential block and offers a curl command instead. --port picks which port to reach. It is required when an app declares more than one; the broker's error lists the ports it exposes, which is the only discovery mechanism. The local listener now defaults to the resolved remote port rather than an engine constant, so a database tunnel still lands on 5432 and an app serving 8080 lands on 8080.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Client half of brainpodnl/brainpod#456, which generalises the tunnel broker from databases to any pod resource that listens on a TCP port.
What changed
OpenSessionRequest.database_idbecameresource_id— field 1 keeps its number and type, so this is a rename, not a wire break — and gained aport. The response carriestarget_kindand the resolved remote port.A
Targetenum replaces the bareDatabaseEnginethat used to thread through the proxy, the banner and the DSN table:127.0.0.1:5432; an app serving 8080 lands on127.0.0.1:8080.curl http://127.0.0.1:<port>/where a database getspsql/mariadb/valkey-cli/sqlcmdplus a DSN.listeningandclosedcarrytargetKind;engineisnullfor apps and thecredentialsevent is emitted for database targets only.--portpicks which port to reach. It is required when an app declares more than one; the broker's error enumerates the ports, which is the only discovery mechanism the protocol offers.Verification
Built the real binary and ran it against a throwaway fake control plane (REST resolve +
TunnelBroker+TunnelService+ an echo backend), since no live environment was available:Bytes really traverse the tunnel. The fake
TunnelServicelogs a failure line ifbrainpod-include-credentialsever arrives; it never did for the app target, confirming the preflight is skipped.--jsonon the same tunnel emits{"event":"listening",...,"targetKind":"app","engine":null,...}and nocredentialsevent.cargo test— 95 pass, including new coverage forTarget::decode(database with engine, app, database without engine, unknown kind), the credential-less app banner, IPv6 bracketing in the app client command, and--portargument parsing.Draft until
brainpodnl/brainpod#456 merges. Against today's production control plane this CLI still works for databases, but an app tunnel needs the new broker fields.