Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add upstream proxy feature - #208

Open
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy
Open

Add upstream proxy feature#208
eraow wants to merge 1 commit into
coder:mainfrom
eraow:feature/upstream-proxy

Conversation

@eraow

Copy link
Copy Markdown

Note: This PR was generated with AI assistance.

Summary

Adds an --upstream-proxy option so Boundary can forward its own outbound
requests through an HTTP(S) proxy. This makes Boundary usable in environments
that only allow internet access via a corporate proxy.

Motivation

I want to run Boundary behind a corporate proxy. Without this option, Boundary
connects directly to upstream hosts, which fails when direct egress is blocked
and only a proxy is permitted.

What this does

  • Adds --upstream-proxy <URL> (env BOUNDARY_UPSTREAM_PROXY, YAML
    upstream_proxy), e.g. http://proxy.corp:3128.
  • When set, Boundary routes its own upstream HTTP/HTTPS requests through the
    given proxy instead of connecting directly. Allow-rule evaluation and audit
    logging still happen first — the upstream proxy only receives already-allowed
    requests.
  • Behavior is unchanged when the flag is not provided.
  • The upstream proxy is a Boundary outbound-transport setting, not a child
    HTTP_PROXY setting. The confined child still sends traffic to Boundary first.

Usage

boundary --upstream-proxy http://proxy.corp:3128 \
--allow "domain=github.com" -- curl https://github.com

Manual verification

PASS (allowed domain)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://github.com
200
$ cat boundary-logs/boundary-2026-07-17_00-08-01-4094015.log
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="boundary session started" session_id=09d4a8ab-7ba4-42ae-a90f-9ff79e37c608
time=2026-07-17T00:08:01.237+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-17T00:08:01.237+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-17T00:08:01.246+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-17T00:08:01.398+09:00 level=INFO msg=ALLOW method=GET url=https://github.com/ host=github.com rule="domain=github.com"
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-17T00:08:01.473+09:00 level=INFO msg="Stop namespace-jail manager"

BLOCK (disallowed domain — never reaches the upstream proxy)

$ ./boundary --upstream-proxy http://${proxy}:3080 --log-level info --log-dir ./boundary-logs --allow "domain=github.com" -- curl -s -o /dev/null -w "%{http_code}" https://example.com
403
$ cat boundary-logs/boundary-2026-07-16_23-11-43-3997580.log
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="boundary session started" session_id=f11a132f-ba27-43a6-a400-13d19da6f790
time=2026-07-16T23:11:43.132+09:00 level=WARN msg="Audit logs are disabled; workspace agent has not created log proxy socket" socket=/tmp/boundary-audit.sock
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Using upstream proxy" upstream_proxy=http://proxy:3080
time=2026-07-16T23:11:43.132+09:00 level=INFO msg="Start namespace-jail manager"
time=2026-07-16T23:11:43.143+09:00 level=INFO msg="Starting HTTP proxy with TLS termination" port=8080
time=2026-07-16T23:11:43.287+09:00 level=WARN msg=DENY method=GET url=https://example.com/ host=example.com
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Command completed, shutting down..."
time=2026-07-16T23:11:43.288+09:00 level=INFO msg="Stop namespace-jail manager"

@eraow
eraow marked this pull request as ready for review July 16, 2026 16:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@eraow