Skip to content
Commit Detail

Commit 0f13422

Author
Gabi Villalonga Simon <gvillalongasimon@cloudflare.com> 2026-01-28 13:12:24 -0600
Parents
0a8d816
Tree
928c723
container: implement egress HTTP routing with sidecar container

Implement the workerd handling for container egress HTTP routing:

- EgressHttpService: HTTP service that handles CONNECT requests from
  proxy-everything (https://hub.docker.com/r/cloudflare/proxy-everything),
  it parses tunneled HTTP requests, and forwards them to the appropriate SubrequestChannel based on registered mappings

- We need to do proxy-everything container management: we create and monitor a sidecar
  container (proxy-everything) that shares network namespace with the
  main container and intercepts outbound traffic via iptables/TPROXY.

- Egress listener: HTTP server listening on the Docker bridge gateway
  that receives proxied requests from proxy-everything.

- setEgressHttp RPC implementation that registers address
  to SubrequestChannel mappings.

WebSocket is currently unimplemented. It's a TODO.

Files changed

2 files changed~2 modified