blog: Pilot node from a locked-down agent VM (Meta Muse) + two tutorials + firewalls doc section - #257
Merged
Conversation
…arning Center tutorials; firewalls doc proxy-only section
- Blog post (Engineering): how a Pilot node registered from inside Meta
Muse's sandbox (no UDP, poisoned DNS, HTTPS CONNECT only), the six dead
ends, and the transparent SNI router + mount-namespace recipe that worked.
Banner SVG in the house style, blogPosts.json entry.
- Learning Center: "Install Pilot Protocol Skills in Meta Muse's Agent VM"
(Foundations) and "Run a Pilot Node Through an HTTPS-Only Egress Proxy"
(Transport), both with FAQ structured data, registered in learnGuides.ts.
- docs/firewalls: new "Proxy-only egress (no direct TCP)" section pointing
at the pilot-sandbox skill and both tutorials; plain twin updated by hand
and re-stamped with the source hash.
- seo.mjs: explicit title for /docs/firewalls ("Running Pilot Behind a
Firewall: Compat Mode Guide"); the auto-fitter was emitting "Running pilot
behind Guide & Reference".
Verified: astro build clean, check:site OK (447 HTML files, 301 public
pages), check:plain OK (45 stamped twins in sync).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Contributor
|
🚀 Preview deployed to Cloudflare Pages
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
/blog/pilot-protocol-from-a-locked-down-agent-sandbox(Engineering): how a Pilot node registered from inside Meta Muse's per-agent VM, where outbound UDP is blocked, DNS for our hostnames is poisoned,/etc/hostsis read-only, and the only egress is an authenticating HTTPSCONNECTproxy. Covers the six dead ends (SNI rewriting breaks the TLS 1.3 transcript, iptables NAT modules missing, LD_PRELOAD cannot hook Go, …) and the transparent SNI router +unshare -mhosts override that worked. Banner SVG in the house style./learn/install-pilot-skills-in-meta-muse(Foundations): one-line installer for the workspace skills folder, install Pilot, bring the daemon online, verify, keep it running./learn/pilot-node-through-https-only-egress-proxy(Transport): diagnose, design, step by step, trust modes, failure table. Applies to any proxy-only container or corporate network.pilot-sandboxskill and both tutorials. Plain twin updated by hand and re-stamped with the new source hash (no Gemini key needed).ROUTE_TITLESentry for/docs/firewalls. The auto-fitter was rendering its<title>as "Running pilot behind Guide & Reference | Pilot Protocol Docs".Verification
npm run buildclean;npm run check:siteOK (447 HTML files, 301 public pages, 37k internal refs);npm run check:plainOK (104 pairs, 45 stamped twins in sync).<title>.sni_router.pythrough an authenticating CONNECT proxy returned the real registry certificate unmodified and reached the beacon with full system-trust verification.Depends on
skills.jsonafter that merges).Site hygiene noted while auditing (not changed here)
https://github.com/pilot-protocol/generallegal-app(404) in the General Legal app-store page. It comes from the app-store metadata API snapshot (src/data/app-metadata.json), so the fix belongs upstream inpilot-protocol/app-templateappstore-meta/data/apps/. Everything else failing was bot-blocking 403s (Medium, MDPI, ScienceDirect, OpenReview) and a PyPI 503.🤖 Generated with Claude Code