Releases: shsingh/opensase
Release list
OpenSASE v0.1.1
OpenSASE v0.1.1
SASE-style TLS inspection edge: OpenVPN → mitmproxy (decrypt/re-encrypt on URL category) → ClamAV → decision log. Fully declarative — every image is a Nix derivation; Kubernetes base manifests render from CUE.
Nix-built OCI images — no Nix required
Images passed the release smoke gate before publication (compose from fresh images; clamd INSTREAM CLEAN/INFECTED probes; decision-log splice/bump assertions): release run.
| Image | Version tag | Digest |
|---|---|---|
opensase-dnsmasq |
0.1.1 |
sha256:e26f5ac2c2fb01c93987b1a4e9f081b154b644b5c51a18550df7336e667d96c4 |
opensase-clamav |
0.1.1 |
sha256:04261993a891ab837326a6e9270897299256626bc90e5a999d5c1ff64196820a |
opensase-mitmproxy |
0.1.1 |
sha256:b139e90dcb9844c20ca30b31a6ad720b7ee660d9c76d15bd8a0b081ed260b74e |
opensase-openvpn |
0.1.1 |
sha256:cd705f310a47b8e24a648b3216381bad957e9e113d3ffdb4887307364620e55d |
Deploy in ~60 seconds
git clone --depth 1 --branch v0.1.1 https://github.com/shsingh/opensase && cd opensase
docker compose -p opensase up -d # mitmproxy :8080 · openvpn udp/5443First client: nix run .#vpn-init && nix run .#vpn-getclient -- <device-cn> — see Client setup. Verdict check: curl -x http://<edge>:8080 https://example.com; an EICAR download should show INFECTED in the decision log.
What shipped
- Fully declarative:
nix/images.nix(fourdockerToolsimages),nix/appliance.nix(NixOS module),k8s/manifests.cue→k8s/manifests.yaml(CUE-rendered Kubernetes base) - PKI tooling as flake apps:
nix run .#vpn-init,nix run .#vpn-getclient - Release pipeline: build → smoke gate → publish (tag-gated;
workflow_dispatch= zero-side-effect rehearsal), signed-tag verification, per-image SPDX SBOMs - Docs site: architecture · deployment · policy · clients · CI & Release · troubleshooting · roadmap · future directions
- Supply chain: signed commits + signed tag, SBOMs, secret scanning + push protection, dependency review, OpenSSF Scorecard + Best Practices (#15121)
Nix users:
nix run .#load-imagesbuilds byte-identical images from the flake.
Lab appliance — do not run unmodified in production.
SBOMs
Per-image SPDX SBOMs attached (sbom-opensase-*.spdx.json).