Skip to content

blog: Pilot node from a locked-down agent VM (Meta Muse) + two tutorials + firewalls doc section - #257

Merged
TeoSlayer merged 1 commit into
mainfrom
blog/pilot-sandbox-muse
Sep 23, 2026
Merged

TeoSlayer merged 1 commit into
mainfrom
blog/pilot-sandbox-muse

Conversation

@TeoSlayer

Copy link
Copy Markdown
Contributor

What

  • Blog post /blog/pilot-protocol-from-a-locked-down-agent-sandbox (Engineering): how a Pilot node registered from inside Meta Muse's per-agent VM, where outbound UDP is blocked, DNS for our hostnames is poisoned, /etc/hosts is read-only, and the only egress is an authenticating HTTPS CONNECT proxy. Covers the six dead ends (SNI rewriting breaks the TLS 1.3 transcript, iptables NAT modules missing, LD_PRELOAD cannot hook Go, …) and the transparent SNI router + unshare -m hosts override that worked. Banner SVG in the house style.
  • Learning Center tutorials
    • /learn/install-pilot-skills-in-meta-muse (Foundations): one-line installer for the workspace skills folder, install Pilot, bring the daemon online, verify, keep it running.
    • /learn/pilot-node-through-https-only-egress-proxy (Transport): diagnose, design, step by step, trust modes, failure table. Applies to any proxy-only container or corporate network.
  • docs/firewalls: new "Proxy-only egress (no direct TCP)" section linking the pilot-sandbox skill and both tutorials. Plain twin updated by hand and re-stamped with the new source hash (no Gemini key needed).
  • seo.mjs: explicit ROUTE_TITLES entry for /docs/firewalls. The auto-fitter was rendering its <title> as "Running pilot behind Guide & Reference | Pilot Protocol Docs".

Verification

  • npm run build clean; npm run check:site OK (447 HTML files, 301 public pages, 37k internal refs); npm run check:plain OK (104 pairs, 45 stamped twins in sync).
  • All three new routes render with their intended <title>.
  • The recipe the post describes was re-tested locally: sni_router.py through an authenticating CONNECT proxy returned the real registry certificate unmodified and reached the beacon with full system-trust verification.

Depends on

Site hygiene noted while auditing (not changed here)

🤖 Generated with Claude Code

…arning Center tutorials; firewalls doc proxy-only section

- Blog post (Engineering): how a Pilot node registered from inside Meta
  Muse's sandbox (no UDP, poisoned DNS, HTTPS CONNECT only), the six dead
  ends, and the transparent SNI router + mount-namespace recipe that worked.
  Banner SVG in the house style, blogPosts.json entry.
- Learning Center: "Install Pilot Protocol Skills in Meta Muse's Agent VM"
  (Foundations) and "Run a Pilot Node Through an HTTPS-Only Egress Proxy"
  (Transport), both with FAQ structured data, registered in learnGuides.ts.
- docs/firewalls: new "Proxy-only egress (no direct TCP)" section pointing
  at the pilot-sandbox skill and both tutorials; plain twin updated by hand
  and re-stamped with the source hash.
- seo.mjs: explicit title for /docs/firewalls ("Running Pilot Behind a
  Firewall: Compat Mode Guide"); the auto-fitter was emitting "Running pilot
  behind Guide & Reference".

Verified: astro build clean, check:site OK (447 HTML files, 301 public
pages), check:plain OK (45 stamped twins in sync).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview deployed to Cloudflare Pages

  • Commit deploy URL: https://9b90e35a.pilotprotocol.pages.dev
  • Branch alias: https://blog/pilot-sandbox-muse.pilotprotocol.pages.dev (may take ~30s to propagate)
  • Commit: 78a05ad7e7c085dac7543aeb01c7d4b7026f116a

@TeoSlayer
TeoSlayer merged commit c8c72a6 into main Sep 23, 2026
3 checks passed
@TeoSlayer
TeoSlayer deleted the blog/pilot-sandbox-muse branch September 23, 2026 10:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants