Skip to content

Tunnel to the rack through Nexus - #66

Draft
plotnick wants to merge 3 commits into
gossip-persistencefrom
nexus-tunnel
Draft

Tunnel to the rack through Nexus#66
plotnick wants to merge 3 commits into
gossip-persistencefrom
nexus-tunnel

Conversation

@plotnick

@plotnick plotnick commented Aug 29, 2026

Copy link
Copy Markdown
Collaborator

Given --nexus, the client carries its connections over authenticated WebSockets to Nexus's support-shell endpoint, which pipes them to a sush proxy. The platform TLS and signed requests inside cross Nexus untouched, so the tech port and the tunnel carry identical traffic.

Requires oxidecomputer/omicron#11199.

plotnick and others added 3 commits August 28, 2026 19:53
Given --nexus, the client carries its connections over authenticated
websockets to Nexus's support-shell endpoint, which pipes them to a
sush proxy. The platform TLS and signed requests inside cross Nexus
untouched, so the tech port and the tunnel carry identical traffic.

Co-Authored-By: Claude Mythos 5 <noreply@anthropic.com>
Like curl --resolve: --nexus-resolve supplies the socket address
while the URL's host still names the server for TLS, standing in
for rack DNS that is not yet populated.

Co-Authored-By: Claude Mythos 5 <noreply@anthropic.com>
Creation already shows the session; the start's echo of the same
line was noise. The explicit three-step start still announces.

Co-Authored-By: Claude Mythos 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant