Skip to content

Credential proxy

The guest sees a placeholder. The key stays outside.

Terminal window
kling run -image toolchain -name payments -egress allowlist -allow example.org
kling machine credential payments -domain api.stripe.com -env STRIPE_API_KEY -f key.txt \
-allow-request 'GET /v1/balance' -allow-request 'GET /v1/charges/*'
  1. The guest gets STRIPE_API_KEY=kling-cred-….
  2. Its resolver sends api.stripe.com to the host’s proxy.
  3. The proxy swaps the placeholder for the key, goes out over verified HTTPS and scrubs the key from any echo.

No MITM: the guest does not trust any CA of ours.

Measured with a “compromised” server inside

Section titled “Measured with a “compromised” server inside”
What it tries With MMDS With the proxy
Read the key reads it only sees the placeholder
Direct HTTPS, bypassing the proxy — blocked
Get it back in an echo yes no, it arrives redacted
Use the proxy for another domain — 403

90 ms median per request versus 363 ms for direct HTTPS.

Terminal window
kling machine credential payments -type postgres -domain db.example.com -user app \
-database appdb -env PGPASSWORD -f db-password.txt

Without TLS towards the LAN, the CLI warns you:

warning: -upstream-tls disable: traffic to 10.0.3.25:5432, including query data, is unencrypted (the password is not: SCRAM-SHA-256 only)
Terminal window
kling machine audit payments -denied -since 1h

Method, host, status and duration. Never the key, headers, bodies or the query.