ts-proxy
╔╦╗┌─┐ ╔═╗╦═╗╔═╗═╗ ╦╦ ╦
║ └─┐ ╠═╝╠╦╝║ ║╔╩╦╝╚╦╝
╩ └─┘ ╩ ╩╚═╚═╝╩ ╚═ ╩
Sovereign Tailscale Proxy
Serverless Sovereign MCP Proxy for Tailscale Network Management (v1.2.2) 0% Hardcode · 100% Flexibility · Strict Alphabetical Order
Part of the KpihX-Labs architecture, ts-proxy is a secure, ephemeral CLI tool that runs inside the docker-host abstraction layer. It acts as an intelligent intermediary between your AI agents (running on Ubuntu/Mac) and the global Tailscale API.
Core Principles
- JSON-RPC 2.0 Paradigm: All business logic commands follow a strict payload-driven model, decoupling API evolution from CLI flag stability.
- Dynamic Sovereign Documentation: Built-in introspection engine extracts rich docstrings and recursive JSON type schemas directly from the source code.
- Strict Alphabetical Ordering: To ensure maintainability and predictable CLI UX, all API methods and CLI commands are sorted alphabetically.
- Zero Hardcoding: All versions, paths, and configurations are dynamically resolved or extracted from
pyproject.tomlandconfig.yaml. - Human-In-The-Loop (HITL) Validation: Critical operations require explicit web-based approval before execution.
Documentation Stack
- CONTRACT.md: The total rigorous usage contract (Prod Facet) and sovereign development guide (Dev Facet). Source of truth for technical specs.
- AGENTS.md: High-level instructions and mantras for AI agents assisting in this repository.
- CHANGELOG.md: Evolution history and versioned releases.
Quick Start Visual
AI Agent ──▶ ts-proxy ──▶ [Docker: Core] ──▶ Tailscale API
│ │
│ └─▶ [HITL Approval Web UI]
└─▶ [Autosave: /tmp/ts-proxy/]
Usage
Discovery & Help
Explore the capabilities and expected JSON schemas directly from your terminal:
# List all available commands with summaries and schemas
ts-proxy do --help
# Get detailed documentation and examples for a specific command
ts-proxy do get-device --help
Business Operations (do namespace)
Commands accept a single JSON payload or a path to a JSON file.
# Simple read operation
ts-proxy do list-devices
# Targeted query with JSON payload
ts-proxy do get-device '{"device_id": "12345"}'
Administrative Control (admin namespace)
# Start a new session
ts-proxy admin login
# Check session status
ts-proxy admin status
Architecture
- Core: Python 3.12 (uv)
- Validation: Pydantic V2 (Strict Payload Firewall)
- Engine: Httpx (Async), Typer (CLI Interface)
- UI: Glassmorphism Web HITL (Approved by KpihX)
- Runtime: Ephemeral Docker Container (
ts-proxy:latest)
Metadata
Release files for ts-proxy 1.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ts_proxy-1.2.0.tar.gz | 28.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ts_proxy-1.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 64.5 kB
Release files / ts_proxy-1.2.0.tar.gz
| Download URL | ts_proxy-1.2.0.tar.gz |
|---|---|
| Size | 28.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7f7fa6bf4c69d59eec3a541436ae5c35b81988988fd8b9709edff723375391d4
|
|
BLAKE2b-256 checksum How to use checksums |
cdbb2836d768953b2226d924cee34ef9e51a7039e944619dfd16701ec5143ddd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.3 {"installer":{"name":"uv","version":"0.10.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / ts_proxy-1.2.0-py3-none-any.whl
| Download URL | ts_proxy-1.2.0-py3-none-any.whl |
|---|---|
| Size | 35.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cddc73b2e2e18cd29630e56f59776a25265c6bf3c79dd22f1dea96cf924f110c
|
|
BLAKE2b-256 checksum How to use checksums |
82f90fc503db7f0b2226cdeb5eb123ecbbcf730c7b1506cc046e32506ade7725
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.3 {"installer":{"name":"uv","version":"0.10.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|