Skip to content

Slice 5a: surface blocked egress attempts (DoD #1) - #296

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
slice-5a-blocked-buffer-surface
May 13, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
slice-5a-blocked-buffer-surface

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

First slice in the Slice 5 egress polish + observability sequence. Closes Slice 5 DoD #1 ("`azureclaw egress blocked` lists every host the agent attempted that the enforcement layer refused").

The router has been populating an in-process `BlockedBuffer` from the forward proxy since S12.f — this slice exposes that buffer to operators without giving the agent any new wire access.

Producer (router)

  • New `BlockedBuffer::snapshot_since(since_unix)` + `top_hosts(since, n)` methods. `snapshot_since` is newest-first by `last_seen_unix`; `top_hosts` aggregates across `(sandbox, port)` by hostname with a deterministic secondary sort for tied counts.
  • 7 unit tests in `egress_blocked.rs` cover filter cutoffs, dedup count carry-through, multi-sandbox/multi-port aggregation, `n=0` early-return, and the `truncate(n)` contract.

Wire surface

```
GET /internal/egress/blocked?since=<rfc3339|unix|-Nm>
GET /internal/egress/blocked/top?window=&n=
```

Both mounted on the admin-gated `protected` router. JSON envelopes carry `schema_version: 1` and RFC 3339 strings alongside raw Unix seconds. Hand-rolled duration + RFC 3339 parsers (no `chrono` dep) with 7 unit + 6 integration tests covering bare seconds, `s/m/h/d` suffixes, relative `-Nm` form, malformed input → `0`, the `n ≤ 100` cap, and the default 5m window.

CLI

```
azureclaw egress blocked [--since 10m] [--top] [--window 1h] [--n 20] [--watch] [--json]
```

Added as a subcommand under `egress` so `--watch`/`--top`/`--since` don't collide with the existing flat-options surface. Mirrors `azureclaw inspect` token-resolution (`router-admin-token` secret first, in-pod `admin-token` file fallback) and uses in-pod `kubectl exec curl` to avoid port-forward collisions. `--watch` loops every 5s with VT clear; `--top` overrides `--since`; `--json` emits raw response.

13 vitest unit tests cover `buildPath`, the renderer surface (HOST/PORT/SANDBOX/LAST_SEEN/COUNT columns, empty-state message, since-filter line, top-N window line) and the `unixToIso(0) === "epoch"` sentinel.

Verification

  • `cargo test -p azureclaw-inference-router` → 849 lib + 8 egress_blocked integration (up from 2)
  • `cargo clippy -p azureclaw-inference-router --all-targets -- -D warnings` clean
  • `cargo fmt --all` clean
  • `npm test` → 692 CLI tests (up from 679; +13 new)
  • `npm run typecheck` / `npm run build` clean

Principles compliance

  • §5 no scaffolding — producer (BlockedBuffer fill from forward proxy) was already live; this PR connects consumer surfaces to it.
  • §6 dev-only + test every new line — every new helper has unit coverage; every new endpoint has integration coverage; every new CLI helper has vitest coverage.

Operator-facing surface for the BlockedBuffer the forward proxy has
been populating since S12.f. Closes Slice 5 DoD #1.

Producer side (inference-router):
- New BlockedBuffer::snapshot_since(since_unix) and top_hosts(since,n)
  methods. snapshot_since sorts newest-first by last_seen_unix;
  top_hosts aggregates by hostname across (sandbox, port) and
  secondary-sorts deterministically by host name for tied counts.
- 7 unit tests cover filter cutoffs, dedup count carry-through,
  multi-sandbox/multi-port aggregation, n=0 early return, and the
  truncate-to-n contract.

Wire surface (routes/internal.rs):
- GET /internal/egress/blocked?since=<rfc3339|unix|-Nm>
- GET /internal/egress/blocked/top?window=<duration>&n=<int>
Both mounted on the admin-gated 'protected' router. JSON envelopes
carry schema_version: 1 and RFC 3339 strings alongside raw Unix
seconds. Hand-rolled duration + RFC 3339 parsers (no chrono dep)
with 7 unit tests + 6 integration tests covering bare seconds,
s/m/h/d suffixes, relative -Nm form, malformed input → 0, the n≤100
cap, and the default 5m window.

CLI (azureclaw egress blocked <sandbox>):
- New subcommand under 'egress' so --watch/--top/--since don't
  collide with the existing flat options surface.
- Mirrors azureclaw inspect token-resolution (router-admin-token
  secret first, in-pod admin-token file fallback) and uses in-pod
  kubectl exec curl to avoid port-forward collisions.
- --watch loops every 5s with VT clear; --top overrides --since
  (window is its own filter); --json emits raw response.
- 13 vitest unit tests for buildPath, renderers, and unixToIso(0).

Tests: 849 router lib + 8 egress_blocked integration (up from 2) +
13 CLI unit. cargo clippy -D warnings + cargo fmt + npm
typecheck/build/test/lint all clean.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 2fd2e66 into dev May 13, 2026
21 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the slice-5a-blocked-buffer-surface branch May 13, 2026 21:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant