dev-mitm-proxy
MITM Proxy
The MITM proxy is the network engine's HTTPS interception boundary. It
intercepts traffic from the air-gapped guest VM, normalizes it into typed facts,
hands a SecurityEvent to the security engine, and preserves allowed runtime
bytes for upstream. Treat it as a system, not a collection of hacks -- every
capability must be general-purpose.
Security boundary
Network code parses transport bytes, routes traffic, and emits typed
SecurityEvent facts. It must not broker credentials, create credential refs,
run CEL/security decisions, or sanitize ledger projections. Those belong to the
security engine plugin rail. Every security plugin has the same data contract:
it receives a SecurityEvent and returns a SecurityEvent; the plugin stage
only controls ordering (preprocess, postprocess, or logging).
There are two materialization paths and they must never be collapsed: