Files
devplacepy/devplacepy/routers/tunnel.py
T
retoor 6514261730 Route container proxies through the leg that is actually reachable
The workspace editor hung for 60s and then 504'd. Three independent faults were
stacked behind that one symptom.

Reachability: editor_target delegated to proxy_target, which returns
CONTAINER_PROXY_HOST plus the published host port and never falls back to the
container. From inside the app container that address crosses docker0 into the
host INPUT chain, whose policy is DROP with an allow-list that does not include
the published port range, so the packet was dropped and the request hung rather
than being refused. Measured from the app container: container_ip:8443 answers
302, gateway:20006 is dropped. One shared reachable_target now prefers the
direct container leg and falls back to the published port, and editor_target
uses tunnel_target as services/containers/CLAUDE.md already required. The same
defect affected /p/{slug} ingress and every tunnel, since all three resolved
through proxy_target.

The recorded measurement that motivated the old order (container_ip times out,
gateway connects) no longer holds: make docker-attach puts the app on the
instances' bridge network, which is what makes the direct leg work.

Duplicate response headers: the forwarding core relayed the upstream Date and
Server alongside the ones the serving layer generates, so every proxied
response carried two of each. Both are singleton headers and duplicating them
is malformed HTTP.

Serialization: WorkspaceViewOut declared flag_reason and three sibling strings
as str, so a NULL column made the workspace page 500 for JSON clients.

Documents the two public hostnames and the devplace.net SSH tunnel, so a future
session does not conclude the site is down after pointing curl --resolve at an
address the hostname does not resolve to, and adds the layered procedure for
diagnosing a production failure.

Verified on production with Playwright over both hostnames: the code-server
login renders and the workbench loads. Suite: 3345 passed.
2026-08-13 12:59:53 +02:00

65 lines
2.2 KiB
Python

# retoor <retoor@molodetz.nl>
import logging
from fastapi import APIRouter, Request, WebSocket
from starlette.responses import Response
from devplacepy.services.containers import activity, api, forward, store
from devplacepy.services.containers.workspace import naming, tunnels
logger = logging.getLogger(__name__)
router = APIRouter()
METHODS = forward.METHODS
def resolve(host: str):
if not naming.is_tunnel_host(host):
return None, None, None, None
row = tunnels.by_hostname(host)
if not row or row.get("status") not in tunnels.SERVING_STATUSES:
return None, None, None, None
instance = store.get_instance(row.get("instance_uid", ""))
if not instance or instance.get("deleted_at"):
return None, None, None, None
if instance.get("suspended_at"):
return row, instance, None, None
if instance.get("status") != store.ST_RUNNING:
return row, instance, None, None
host, port = api.tunnel_target(instance, int(row.get("container_port") or 0))
return row, instance, host, port
async def handle_http(request: Request, path: str) -> Response:
host = request.headers.get("host", "")
row, instance, gateway, port = resolve(host)
if row is None:
return Response("no tunnel is published at this address", status_code=404)
if instance is not None and instance.get("suspended_at"):
return Response("this workspace is suspended", status_code=403)
if not gateway or not port:
return Response("the tunnel has no reachable port", status_code=502)
return await forward.proxy_http(
request,
gateway,
port,
path,
on_complete=lambda sent: record_traffic(instance["uid"], row["uid"], sent),
)
def record_traffic(instance_uid: str, tunnel_uid: str, sent: int) -> None:
activity.touch(instance_uid, egress_bytes=sent)
tunnels.record_hit(tunnel_uid, sent)
async def handle_ws(websocket: WebSocket, path: str) -> None:
host = websocket.headers.get("host", "")
row, instance, gateway, port = resolve(host)
if row is None or instance is None or not gateway or not port:
await websocket.close(code=1011)
return
activity.touch(instance["uid"])
await forward.proxy_ws(websocket, gateway, port, path)