[PSU-1420] fix(agent): use TLS for PSU gRPC over HTTPS - #2017
Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
Conversation
The PSU agent sent plaintext HTTP/2 to HTTPS URLs because tonic lacked TLS support and from_shared did not configure it. Enable native-root TLS and construct the endpoint with scheme-aware configuration while keeping HTTP connections unchanged. Issue: PSU-1420 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Implementation notes:
Note LLM-assisted content (no human feedback). |
Let maintainers know that an action is required on their side
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation correctly enables trusted TLS for HTTPS without regressing plaintext HTTP support.
Review effort: Balanced
Findings: None
What changed in this PR
Enables secure PSU gRPC registration over HTTPS while preserving HTTP compatibility.
Changes:
- Enables tonic TLS with native certificate roots.
- Builds scheme-aware PSU endpoints and adds protocol regression tests.
- Documents HTTPS certificate trust requirements.
| File | Description |
|---|---|
devolutions-agent/Cargo.toml |
Enables tonic native-root TLS. |
devolutions-agent/src/psu_agent/mod.rs |
Configures HTTPS endpoints and tests TLS/HTTP behavior. |
Cargo.lock |
Records new TLS dependencies. |
package/AgentLinux/README.md |
Documents HTTPS container setup. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
d0f13ef
into
master
The Devolutions Agent can now register with PowerShell Universal over HTTPS. Previously, its gRPC client sent plaintext HTTP/2 to HTTPS endpoints because tonic TLS support was disabled and endpoint construction did not configure TLS from the URL. The connection now uses native certificate roots for HTTPS while retaining plaintext HTTP support.
A regression test reproduced the plaintext preface before the fix and verifies a TLS ClientHello afterward. All 76 Agent library tests and workspace Clippy pass. Against isolated PSU 2026.3.1.0, the locally built Linux Agent registered over trusted-certificate HTTPS; an untrusted certificate was rejected, and HTTP gRPC registration still worked. The full workspace test run could not pass on this Windows host: an unrelated example hit a linker file lock, and three package-broker reparse-point tests require a privilege this process lacks.
Issue: PSU-1420