Skip to content

Releases: shsingh/opensase

Release list

OpenSASE v0.1.1

Choose a tag to compare

@shsingh shsingh released this 01 Oct 04:44
v0.1.1
76179f2

OpenSASE v0.1.1

SASE-style TLS inspection edge: OpenVPN → mitmproxy (decrypt/re-encrypt on URL category) → ClamAV → decision log. Fully declarative — every image is a Nix derivation; Kubernetes base manifests render from CUE.

Nix-built OCI images — no Nix required

Images passed the release smoke gate before publication (compose from fresh images; clamd INSTREAM CLEAN/INFECTED probes; decision-log splice/bump assertions): release run.

Image Version tag Digest
opensase-dnsmasq 0.1.1 sha256:e26f5ac2c2fb01c93987b1a4e9f081b154b644b5c51a18550df7336e667d96c4
opensase-clamav 0.1.1 sha256:04261993a891ab837326a6e9270897299256626bc90e5a999d5c1ff64196820a
opensase-mitmproxy 0.1.1 sha256:b139e90dcb9844c20ca30b31a6ad720b7ee660d9c76d15bd8a0b081ed260b74e
opensase-openvpn 0.1.1 sha256:cd705f310a47b8e24a648b3216381bad957e9e113d3ffdb4887307364620e55d

Deploy in ~60 seconds

git clone --depth 1 --branch v0.1.1 https://github.com/shsingh/opensase && cd opensase
docker compose -p opensase up -d        # mitmproxy :8080 · openvpn udp/5443

First client: nix run .#vpn-init && nix run .#vpn-getclient -- <device-cn> — see Client setup. Verdict check: curl -x http://<edge>:8080 https://example.com; an EICAR download should show INFECTED in the decision log.

What shipped

  • Fully declarative: nix/images.nix (four dockerTools images), nix/appliance.nix (NixOS module), k8s/manifests.cue → k8s/manifests.yaml (CUE-rendered Kubernetes base)
  • PKI tooling as flake apps: nix run .#vpn-init, nix run .#vpn-getclient
  • Release pipeline: build → smoke gate → publish (tag-gated; workflow_dispatch = zero-side-effect rehearsal), signed-tag verification, per-image SPDX SBOMs
  • Docs site: architecture · deployment · policy · clients · CI & Release · troubleshooting · roadmap · future directions
  • Supply chain: signed commits + signed tag, SBOMs, secret scanning + push protection, dependency review, OpenSSF Scorecard + Best Practices (#15121)

Nix users: nix run .#load-images builds byte-identical images from the flake.
Lab appliance — do not run unmodified in production.

SBOMs

Per-image SPDX SBOMs attached (sbom-opensase-*.spdx.json).