Commit Graph
8 Commits
Author SHA1 Message Date
Sahilb315 472a3e859a docs(ebpf-poc): setup guide and CA trust findings
SETUP.md walks a fresh Linux machine through the POC end to end, in
short numbered steps.

The design doc gains two measured sections. CA Trust records which
clients honour the system trust store and which ship their own roots,
along with the config file settings that work without environment
variables. Container Reachability records that the hook does reach into
containers but the redirect target does not, because loopback is
network namespaced.
2026-07-28 17:47:58 +05:30
Sahilb315 d987512ccf feat(ebpf-poc): manage the proxy CA and npm trust
Redirecting a package manager into the proxy is only half the job. The
client then has to trust the proxy's certificate, and npm will not,
because Node from nodejs.org compiles its own roots into the binary and
ignores the system trust store.

Adds `pmgwatch ca` with install, status and remove.

install persists a CA keypair through PMG's own certmanager, so the
certificate survives a proxy restart. Without a persisted CA the daemon
generates an ephemeral one on every start and trust has to be redone
each time. The private key is left owned by the proxy user at 0600, and
a separate public bundle is written for npm, so npm never needs access
to the key.

npm is configured through `npm config set cafile --location=user`, run
as the target user. Environment variables that could shadow that config
are stripped from the child so the read-back verification is
meaningful. The previous cafile is recorded and restored on remove.

install refuses to run while the proxy is up, since the daemon reads the
certificate at startup, and refuses to change options against existing
state so a half-migrated setup cannot happen.
2026-07-28 17:47:47 +05:30
Sahilb315 60f2565145 feat(ebpf-poc): derive proxy target and exemption from state 2026-07-27 21:17:47 +05:30
Sahilb315 a4b99e40e7 feat(ebpf-poc): redirect eligible connections to the proxy
Turns the recorded ACTION_REDIRECT decision into an actual rewrite of
user_ip4 and user_port, so a connection that would have reached the
registry directly lands on the configured target instead.

The target address is copied out of the map as is. It is already held
in network byte order, the same layout as ctx->user_ip4, so converting
it again silently corrupts the destination: 127.0.0.1 becomes 1.0.0.127,
which is routable, never answers, and shows up as a two minute hang
rather than an error. Only the port is converted, since it is kept in
host order for the userspace side.

Verified against a dummy listener. curl to an external HTTPS host is
logged as REDIRECT against its original destination, and the TLS
ClientHello arrives on the local target.
2026-07-27 14:18:47 +05:30
Sahilb315 05a484ea5e implement decision logic 2026-07-27 13:51:09 +05:30
Sahilb315 b8e12c27ae fix main.go 2026-07-24 22:54:20 +05:30
Sahilb315 da6e10d2ad add protocol field 2026-07-24 22:40:35 +05:30
Sahilb315 3e1ece3257 visibility setup with ebpf 2026-07-24 21:23:23 +05:30