Credential proxy
The guest sees a placeholder. The key stays outside.
kling run -image toolchain -name payments -egress allowlist -allow example.orgkling machine credential payments -domain api.stripe.com -env STRIPE_API_KEY -f key.txt \ -allow-request 'GET /v1/balance' -allow-request 'GET /v1/charges/*'- The guest gets
STRIPE_API_KEY=kling-cred-…. - Its resolver sends
api.stripe.comto the host’s proxy. - The proxy swaps the placeholder for the key, goes out over verified HTTPS and scrubs the key from any echo.
No MITM: the guest does not trust any CA of ours.
Measured with a “compromised” server inside
Section titled “Measured with a “compromised” server inside”| What it tries | With MMDS | With the proxy |
|---|---|---|
| Read the key | reads it | only sees the placeholder |
| Direct HTTPS, bypassing the proxy | — | blocked |
| Get it back in an echo | yes | no, it arrives redacted |
| Use the proxy for another domain | — | 403 |
90 ms median per request versus 363 ms for direct HTTPS.
Postgres
Section titled “Postgres”kling machine credential payments -type postgres -domain db.example.com -user app \ -database appdb -env PGPASSWORD -f db-password.txtWithout TLS towards the LAN, the CLI warns you:
warning: -upstream-tls disable: traffic to 10.0.3.25:5432, including query data, is unencrypted (the password is not: SCRAM-SHA-256 only)kling machine audit payments -denied -since 1hMethod, host, status and duration. Never the key, headers, bodies or the query.