headroom/crates/headroom-proxy/Cargo.toml
dependabot[bot] 322425c43b
deps: bump sha2 from 0.10.9 to 0.11.0 (#2288)
Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to
0.11.0.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="ffe093984c"><code>ffe0939</code></a>
Release sha2 0.11.0 (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/806">#806</a>)</li>
<li><a
href="8991b65fe4"><code>8991b65</code></a>
Use the standard order of the <code>[package]</code> section fields (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/807">#807</a>)</li>
<li><a
href="3d2bc57db4"><code>3d2bc57</code></a>
sha2: refactor backends (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/802">#802</a>)</li>
<li><a
href="faa55fb836"><code>faa55fb</code></a>
sha3: bump <code>keccak</code> to v0.2 (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/803">#803</a>)</li>
<li><a
href="d3e6489e56"><code>d3e6489</code></a>
sha3 v0.11.0-rc.9 (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/801">#801</a>)</li>
<li><a
href="bbf6f51ff9"><code>bbf6f51</code></a>
sha2: tweak backend docs (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/800">#800</a>)</li>
<li><a
href="155dbbf295"><code>155dbbf</code></a>
sha3: add default value for the <code>DS</code> generic parameter on
<code>TurboShake128/256</code>...</li>
<li><a
href="ed514f2b34"><code>ed514f2</code></a>
Use published version of <code>keccak</code> v0.2 (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/799">#799</a>)</li>
<li><a
href="702bcd8373"><code>702bcd8</code></a>
Migrate to closure-based <code>keccak</code> (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/796">#796</a>)</li>
<li><a
href="827c043f82"><code>827c043</code></a>
sha3 v0.11.0-rc.8 (<a
href="https://redirect.github.com/RustCrypto/hashes/issues/794">#794</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0">compare
view</a></li>
</ul>
</details>
<br />

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: JerrettDavis <mxjerrett@gmail.com>
2026-08-14 16:40:45 -05:00

120 lines
5.5 KiB
TOML

[package]
name = "headroom-proxy"
version = "0.1.0"
edition.workspace = true
rust-version.workspace = true
license.workspace = true
repository.workspace = true
description = "Headroom transparent reverse proxy (Rust, axum). Phase 1: drop-in passthrough in front of the Python proxy."
[[bin]]
name = "headroom-proxy"
path = "src/main.rs"
[lib]
name = "headroom_proxy"
path = "src/lib.rs"
[dependencies]
axum = { workspace = true, features = ["ws", "http2", "macros"] }
tokio = { workspace = true, features = ["macros", "rt-multi-thread", "signal", "net", "io-util", "time"] }
tower = { workspace = true }
tower-http = { version = "0.7", features = ["trace", "request-id", "util"] }
tracing = { workspace = true }
tracing-subscriber = { version = "0.3", features = ["json", "env-filter", "fmt"] }
reqwest = { version = "0.12", default-features = false, features = ["stream", "rustls-tls", "http2"] }
tokio-tungstenite = { version = "0.30", default-features = false, features = ["connect", "rustls-tls-webpki-roots"] }
clap = { workspace = true, features = ["derive", "env"] }
serde = { workspace = true }
serde_json = { workspace = true }
thiserror = { workspace = true }
uuid = { version = "1", features = ["v4"] }
bytes = { workspace = true }
futures = "0.3"
futures-util = "0.3"
pin-project-lite = "0.2"
http = "1"
http-body-util = "0.1"
hyper = "1"
url = "2"
humantime = "2"
bytesize = "2"
tokio-util = { version = "0.7" }
headroom-core = { path = "../headroom-core" }
# Phase D PR-D1: native Bedrock InvokeModel route. SigV4 + AWS
# default credential chain.
aws-sigv4 = { workspace = true }
aws-config = { workspace = true }
aws-credential-types = { workspace = true }
aws-smithy-runtime-api = { workspace = true }
# Phase D PR-D2: Bedrock binary EventStream parser. AWS frames each
# message with a CRC32 over the prelude and over the entire message;
# `crc32fast` is the standard IEEE 802.3 implementation already
# transitively pulled in by `aws-smithy-*` (so this is not an
# additional cold dep — promoting to a direct one for clarity).
crc32fast = "1"
# Phase D PR-D3: Prometheus metrics for Bedrock observability. The
# `prometheus` crate's default-features pull in `protobuf`, which we
# don't need (we serve text-format scrapes only), so we disable
# defaults and re-enable nothing — pure registry + counter +
# histogram + text encoder is sufficient.
#
# H4 fix: the H3 force-zero contract (in
# `observability::prometheus::handle_metrics`) relies on this
# crate's v0.13 `gather()` semantics — empty MetricVec families are
# omitted from the scrape, so we force-touch each counter / gauge
# with a sentinel label to surface HELP/TYPE on boot. Pinning the
# exact patch version (no caret, no `~`) so a future minor-version
# bump cannot silently change the alarm contract; the bump must be
# an explicit code review that re-validates the contract.
prometheus = { version = "=0.14.0", default-features = false }
# PR-E6: SHA-256 over canonical bytes of the cache hot zone (system,
# tools, early messages) for cache-bust drift detection. Already in
# the dev-dependencies (and pulled transitively by `aws-sigv4` via
# `aws-smithy-runtime-api`); promoted here to a direct, normal-build
# dependency so the drift detector compiles outside `cfg(test)`. Also
# used by PR-E4 for `prompt_cache_key` derivation.
sha2 = "0.11"
# PR-E6: bounded session-scoped cache of structural hashes. The
# detector evicts the oldest session at 1000 entries — we never want
# unbounded memory growth from a flood of unique session keys. `lru`
# is the de-facto Rust LRU crate; minimal surface, no dependencies of
# our own beyond `hashbrown` (which we already pull transitively).
lru = "0.18"
# PR-D4: GCP Application Default Credentials → bearer token for
# Vertex `:rawPredict` / `:streamRawPredict`. See workspace
# Cargo.toml for rationale.
gcp_auth = { workspace = true }
async-trait = "0.1"
# Phase E PR-E1: tool array deterministic sort uses MD5 of canonical
# JSON as a fallback sort key for unnamed tools. MD5 is sufficient
# because the value is opaque and only used for stable in-process
# ordering — never persisted, never compared cross-host. Same crate
# the core uses for the CCR cache_key, so no additional hash backend
# enters the dep tree.
md-5 = "0.10"
[dev-dependencies]
tower = { workspace = true, features = ["util"] }
wiremock = "0.6"
reqwest = { version = "0.12", default-features = false, features = ["stream", "rustls-tls", "http2", "json"] }
tokio-tungstenite = { version = "0.30", default-features = false, features = ["connect", "rustls-tls-webpki-roots"] }
futures-util = "0.3"
tokio = { workspace = true, features = ["macros", "rt-multi-thread", "signal", "net", "io-util", "time", "test-util", "process"] }
hyper = { version = "1", features = ["server", "http1", "http2"] }
hyper-util = { version = "0.1", features = ["tokio", "server-auto"] }
http-body-util = "0.1"
tokio-stream = "0.1"
# PR-A1 cache-safety tests assert SHA-256 byte-equality between the
# inbound and upstream-received bodies. The hash is the only sound
# way to gate "the proxy did not perturb the request" because JSON
# value-equality misses whitespace, key order, and Unicode escape
# differences that all bust the prompt cache.
sha2 = "0.11"
# PR-C1: property tests for the byte-level SSE parser. The parser
# must never panic on arbitrary input bytes (TCP can hand us anything,
# including malformed UTF-8 split mid-codepoint or fuzz-generated
# noise). 100K cases is the project default for "no panic" parser
# invariants — see `feedback_realignment_build_constraints.md`.
proptest = "1"
headroom-simulators = { path = "../headroom-simulators" }