feat(proxy): containerized Claude Code client on isolated bridge
Adds proxy/ — a docker compose that routes Claude Code through proxy.fhirworx.io from any host, parallel to the WSL/systemd bootstrap in dev/scripts/setup-proxy-client.sh. cf-proxy (cloudflared access tcp) and claude run on an inline 192.168.10.0/24 bridge. cf-proxy is pinned to .2 and claude reaches it by hostname via extra_hosts so the TLS SNI to proxy.fhirworx.io resolves correctly without sharing /etc/hosts with cloudflared. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
7
proxy/.env.example
Normal file
7
proxy/.env.example
Normal file
@@ -0,0 +1,7 @@
|
||||
# Password for the squid 'claude' user (see infra/squid/passwd on the host).
|
||||
PROXY_PASSWORD=
|
||||
|
||||
# Cloudflare Access service token for proxy.fhirworx.io.
|
||||
# Mint a new pair under Zero Trust → Access → Service Auth.
|
||||
CF_ACCESS_CLIENT_ID=
|
||||
CF_ACCESS_CLIENT_SECRET=
|
||||
13
proxy/Dockerfile
Normal file
13
proxy/Dockerfile
Normal file
@@ -0,0 +1,13 @@
|
||||
# Containerized Claude Code client — proxied via cf-proxy (sibling service).
|
||||
# Mirrors what dev/scripts/setup-proxy-client.sh does on a WSL host, minus the
|
||||
# systemd/hosts hackery (compose handles networking + extra_hosts).
|
||||
FROM node:20-bookworm-slim
|
||||
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
ca-certificates curl git jq openssh-client \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
RUN npm install -g @anthropic-ai/claude-code
|
||||
|
||||
ENTRYPOINT ["claude"]
|
||||
66
proxy/compose.yml
Normal file
66
proxy/compose.yml
Normal file
@@ -0,0 +1,66 @@
|
||||
# Run Claude Code through proxy.fhirworx.io from inside containers.
|
||||
#
|
||||
# Two services on a self-contained 192.168.10.0/24 bridge:
|
||||
# cf-proxy cloudflared access TCP shim — terminates the Cloudflare tunnel
|
||||
# on 192.168.10.2:18443. Equivalent to the systemd --user unit
|
||||
# that dev/scripts/setup-proxy-client.sh installs on a WSL host.
|
||||
# claude Claude Code CLI. Reaches cloudflared via the bridge; extra_hosts
|
||||
# pins proxy.fhirworx.io -> 192.168.10.2 so TLS SNI/cert match
|
||||
# without poisoning cf-proxy's own DNS view.
|
||||
#
|
||||
# Usage:
|
||||
# cp .env.example .env && $EDITOR .env # set PROXY_PASSWORD and
|
||||
# CF_ACCESS_CLIENT_ID/SECRET
|
||||
# docker compose run --rm claude # interactive session
|
||||
# docker compose run --rm claude -p 'ping' # one-shot
|
||||
#
|
||||
# Notes:
|
||||
# - claude-home is a named volume so login state persists across runs.
|
||||
# - Bind mounts use identical host/container paths so Claude never sees a
|
||||
# translated path: /home/care/acoharmony, /opt/s3/data/workspace,
|
||||
# /opt/s3/data/notebooks.
|
||||
|
||||
services:
|
||||
cf-proxy:
|
||||
image: cloudflare/cloudflared:latest
|
||||
container_name: cc-cf-proxy
|
||||
command: access tcp --hostname proxy.fhirworx.io --url 0.0.0.0:18443
|
||||
environment:
|
||||
TUNNEL_SERVICE_TOKEN_ID: ${CF_ACCESS_CLIENT_ID}
|
||||
TUNNEL_SERVICE_TOKEN_SECRET: ${CF_ACCESS_CLIENT_SECRET}
|
||||
networks:
|
||||
proxy_net:
|
||||
ipv4_address: 192.168.10.2
|
||||
restart: unless-stopped
|
||||
|
||||
claude:
|
||||
image: git.fhirworx.io/kert/claude:latest
|
||||
container_name: cc-claude
|
||||
depends_on:
|
||||
- cf-proxy
|
||||
networks:
|
||||
- proxy_net
|
||||
extra_hosts:
|
||||
- "proxy.fhirworx.io:192.168.10.2"
|
||||
environment:
|
||||
HTTPS_PROXY: "https://claude:${PROXY_PASSWORD}@proxy.fhirworx.io:18443"
|
||||
HTTP_PROXY: "https://claude:${PROXY_PASSWORD}@proxy.fhirworx.io:18443"
|
||||
NO_PROXY: "localhost,127.0.0.1"
|
||||
working_dir: /home/care/acoharmony
|
||||
volumes:
|
||||
- claude-home:/root/.claude
|
||||
- /home/care/acoharmony:/home/care/acoharmony
|
||||
- /opt/s3/data/workspace:/opt/s3/data/workspace
|
||||
- /opt/s3/data/notebooks:/opt/s3/data/notebooks
|
||||
stdin_open: true
|
||||
tty: true
|
||||
|
||||
networks:
|
||||
proxy_net:
|
||||
driver: bridge
|
||||
ipam:
|
||||
config:
|
||||
- subnet: 192.168.10.0/24
|
||||
|
||||
volumes:
|
||||
claude-home:
|
||||
Reference in New Issue
Block a user