mirror of
https://github.com/turnstonelabs/turnstone.git
synced 2026-08-12 23:12:23 -06:00
10165bb8a1
* feat: add OpenShell sandbox policy for turnstone-server Curated policy for running turnstone-server inside an OpenShell sandbox with kernel-enforced security boundaries (Landlock, netns, seccomp). - Filesystem: workdir read-write, /usr+/etc read-only, /tmp+/dev/null read-write, Landlock best_effort compatibility - Network: default-deny with allowlisted LLM APIs (OpenAI, Anthropic), Tavily, skills.sh, GitHub (read-only L7), MCP registry (read-only L7), Redis localhost, package registries, curated web_fetch domains - Git: L7-enforced read-only (info/refs + git-upload-pack only) - Process: privilege drop to sandbox:sandbox - Inference routing template for credential isolation (real API keys never enter the sandbox, resolved at proxy layer) * fix: address PR #128 review feedback + add integration guide Review fixes: - Use python3 (not python) in usage examples to match binary allowlist - Fix network_policy → network_policies in comment - Remove /usr/bin/git from github_api (git uses github.com not api.github.com; already covered by git_operations policy) - Remove pip/uv from bash_network_tools (package_registries already covers their PyPI access; no need for StackOverflow/Wikipedia reach) - Restructure routes.yaml so commented blocks are indented under routes: key (uncomment without restructuring YAML) New: docs/openshell.md covering policy customization, inference routing, domain allowlisting, MCP subprocess inheritance, and the dual-layer security model.
50 lines
1.5 KiB
YAML
50 lines
1.5 KiB
YAML
# OpenShell inference routing for Turnstone.
|
|
#
|
|
# When using inference routing, the sandbox process connects to
|
|
# https://inference.local instead of the real LLM API. The OpenShell
|
|
# proxy intercepts, rewrites credentials, and forwards to the backend.
|
|
#
|
|
# This keeps real API keys out of the sandbox entirely — the process
|
|
# only sees opaque placeholder tokens in its environment.
|
|
#
|
|
# Usage:
|
|
# openshell sandbox run \
|
|
# --inference-routes deploy/openshell/routes.yaml \
|
|
# ...
|
|
#
|
|
# Then start turnstone with:
|
|
# python3 -m turnstone.server --base-url https://inference.local
|
|
#
|
|
# CUSTOMIZE: uncomment one of the provider blocks below.
|
|
|
|
routes:
|
|
|
|
# --- OpenAI ---
|
|
# - name: inference.local
|
|
# endpoint: https://api.openai.com/v1
|
|
# model: gpt-5
|
|
# provider_type: openai
|
|
# protocols:
|
|
# - openai_chat_completions
|
|
# - model_discovery
|
|
# api_key_env: OPENAI_API_KEY
|
|
|
|
# --- Anthropic ---
|
|
# - name: inference.local
|
|
# endpoint: https://api.anthropic.com
|
|
# model: claude-sonnet-4-6
|
|
# provider_type: anthropic
|
|
# protocols:
|
|
# - anthropic_messages
|
|
# api_key_env: ANTHROPIC_API_KEY
|
|
|
|
# --- Local model server (vLLM / llama.cpp) ---
|
|
# No secret resolution needed — local servers typically have no auth.
|
|
# Omit both api_key and api_key_env to skip credential injection.
|
|
# - name: inference.local
|
|
# endpoint: http://localhost:8000/v1
|
|
# model: meta-llama/Llama-3.1-70B-Instruct
|
|
# protocols:
|
|
# - openai_chat_completions
|
|
# - model_discovery
|