Repository navigation
Slice 5a: surface blocked egress attempts (DoD #1) - #296
Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit intoMay 13, 2026
Merged
Conversation
Operator-facing surface for the BlockedBuffer the forward proxy has been populating since S12.f. Closes Slice 5 DoD #1. Producer side (inference-router): - New BlockedBuffer::snapshot_since(since_unix) and top_hosts(since,n) methods. snapshot_since sorts newest-first by last_seen_unix; top_hosts aggregates by hostname across (sandbox, port) and secondary-sorts deterministically by host name for tied counts. - 7 unit tests cover filter cutoffs, dedup count carry-through, multi-sandbox/multi-port aggregation, n=0 early return, and the truncate-to-n contract. Wire surface (routes/internal.rs): - GET /internal/egress/blocked?since=<rfc3339|unix|-Nm> - GET /internal/egress/blocked/top?window=<duration>&n=<int> Both mounted on the admin-gated 'protected' router. JSON envelopes carry schema_version: 1 and RFC 3339 strings alongside raw Unix seconds. Hand-rolled duration + RFC 3339 parsers (no chrono dep) with 7 unit tests + 6 integration tests covering bare seconds, s/m/h/d suffixes, relative -Nm form, malformed input → 0, the n≤100 cap, and the default 5m window. CLI (azureclaw egress blocked <sandbox>): - New subcommand under 'egress' so --watch/--top/--since don't collide with the existing flat options surface. - Mirrors azureclaw inspect token-resolution (router-admin-token secret first, in-pod admin-token file fallback) and uses in-pod kubectl exec curl to avoid port-forward collisions. - --watch loops every 5s with VT clear; --top overrides --since (window is its own filter); --json emits raw response. - 13 vitest unit tests for buildPath, renderers, and unixToIso(0). Tests: 849 router lib + 8 egress_blocked integration (up from 2) + 13 CLI unit. cargo clippy -D warnings + cargo fmt + npm typecheck/build/test/lint all clean. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First slice in the Slice 5 egress polish + observability sequence. Closes Slice 5 DoD #1 ("`azureclaw egress blocked` lists every host the agent attempted that the enforcement layer refused").
The router has been populating an in-process `BlockedBuffer` from the forward proxy since S12.f — this slice exposes that buffer to operators without giving the agent any new wire access.
Producer (router)
Wire surface
```
GET /internal/egress/blocked?since=<rfc3339|unix|-Nm>
GET /internal/egress/blocked/top?window=&n=
```
Both mounted on the admin-gated `protected` router. JSON envelopes carry `schema_version: 1` and RFC 3339 strings alongside raw Unix seconds. Hand-rolled duration + RFC 3339 parsers (no `chrono` dep) with 7 unit + 6 integration tests covering bare seconds, `s/m/h/d` suffixes, relative `-Nm` form, malformed input → `0`, the `n ≤ 100` cap, and the default 5m window.
CLI
```
azureclaw egress blocked [--since 10m] [--top] [--window 1h] [--n 20] [--watch] [--json]
```
Added as a subcommand under `egress` so `--watch`/`--top`/`--since` don't collide with the existing flat-options surface. Mirrors `azureclaw inspect` token-resolution (`router-admin-token` secret first, in-pod `admin-token` file fallback) and uses in-pod `kubectl exec curl` to avoid port-forward collisions. `--watch` loops every 5s with VT clear; `--top` overrides `--since`; `--json` emits raw response.
13 vitest unit tests cover `buildPath`, the renderer surface (HOST/PORT/SANDBOX/LAST_SEEN/COUNT columns, empty-state message, since-filter line, top-N window line) and the `unixToIso(0) === "epoch"` sentinel.
Verification
Principles compliance