- Request ID:
- 0d8ba4ac-92ed-417f-a494-65f1a10dc911
- Conversation ID:
- 4a0ccb8d-bd2d-43ce-8687-64fc18325999
- Parent Request:
- 19f079dd-f54e-42e2-8d92-702a4d45511c
- Branch:
- subtask_3
- Domain:
- localhost:3000
- Model:
- claude-opus-4-20250514
- Timestamp:
- 7/23/2025, 8:40:59 AM
- Tokens:
- Input: 2 Output: 98 Total: 100
- Cost:
- $0.0074
- Duration:
- 5s
- Status:
- 200
Finally, let me update the ADR index to include the new ADR:
Tool Use: Read (ID: toolu_01WFSyD2BnWSoND6Zv93Hbs7)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/04-Architecture/ADRs/README.md"
}
Tool Result (ID: toolu_01PN7mUJFKBgwJtJLcQzKQiR)
The file /home/crystalin/projects/claude-nexus-proxy/.env.example has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
7β
8β# PostgreSQL connection string
9βDATABASE_URL=postgresql://user:pas...
Show more (11 lines)
Tool Result (ID: toolu_01PN7mUJFKBgwJtJLcQzKQiR)
The file /home/crystalin/projects/claude-nexus-proxy/.env.example has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
7β
8β# PostgreSQL connection string
9βDATABASE_URL=postgresql://user:password@localhost:5432/claude_nexus
10β
11β# Dashboard authentication key (generate with: openssl rand -base64 32)
12β# β οΈ CRITICAL: Without this, dashboard runs WITHOUT authentication, exposing ALL data!
13β# NEVER leave this unset in production!
14βDASHBOARD_API_KEY=your-secure-dashboard-key-here
15β
16β# ===================
17β# Claude API Settings
18β# ===================
Show less
Tool Use: Edit (ID: toolu_01PN7mUJFKBgwJtJLcQzKQiR)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/.env.example",
"new_string": "# Dashboard authentication key (generate with: openssl rand -base64 32)\n# β οΈ CRITICAL: Without this, dashboard runs WITHOUT authentication, ...
Show more (4 lines)
Tool Use: Edit (ID: toolu_01PN7mUJFKBgwJtJLcQzKQiR)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/.env.example",
"new_string": "# Dashboard authentication key (generate with: openssl rand -base64 32)\n# β οΈ CRITICAL: Without this, dashboard runs WITHOUT authentication, exposing ALL data!\n# NEVER leave this unset in production!\nDASHBOARD_API_KEY=your-secure-dashboard-key-here",
"old_string": "# Dashboard authentication key (generate with: openssl rand -base64 32)\nDASHBOARD_API_KEY=your-secure-dashboard-key-here"
}
Show less
Tool Result (ID: toolu_0121d2pdGQLrcPWfyxQknBFf)
1β# Claude Nexus Proxy Configuration Example
2β# Copy this file to .env and update with your values
3β
4β# ===================
5β# Required Settings
6β# ===================
7β
8β# PostgreSQL connection ...
Show more (49 lines)
Tool Result (ID: toolu_0121d2pdGQLrcPWfyxQknBFf)
1β# Claude Nexus Proxy Configuration Example
2β# Copy this file to .env and update with your values
3β
4β# ===================
5β# Required Settings
6β# ===================
7β
8β# PostgreSQL connection string
9βDATABASE_URL=postgresql://user:password@localhost:5432/claude_nexus
10β
11β# Dashboard authentication key (generate with: openssl rand -base64 32)
12βDASHBOARD_API_KEY=your-secure-dashboard-key-here
13β
14β# ===================
15β# Claude API Settings
16β# ===================
17β
18β# API keys are managed through credential files in the credentials/ directory
19β# See credentials/README.md for setup instructions
20β
21β# Directory for domain credential files (default: ./credentials)
22βCREDENTIALS_DIR=./credentials
23β
24β# ===================
25β# Service Configuration
26β# ===================
27β
28β# Proxy service
29βPORT=3000
30βHOST=0.0.0.0
31β
32β# Dashboard service
33βDASHBOARD_PORT=3001
34βDASHBOARD_HOST=0.0.0.0
35β
36β# ===================
37β# Feature Flags
38β# ===================
39β
40β# Enable request/response storage (default: false)
41βSTORAGE_ENABLED=true
42β
43β# Enable debug logging - masks sensitive data (default: false)
44βDEBUG=false
45β
46β# Enable SQL query logging (default: false)
47β# Shows all SQL queries in debug logs when running the application
48βDEBUG_SQL=false
49β
50β# Require client authentication (default: true)
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
Show less
Now let me check if there's a .env.example file that needs updating:
Tool Use: Read (ID: toolu_0121d2pdGQLrcPWfyxQknBFf)
{
"limit": 50,
"file_path": "/home/crystalin/projects/claude-nexus-proxy/.env.example"
}
Tool Result (ID: toolu_016DojYQCR2hACNVRgd8zZrW)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
480β
481β# Check proxy logs
482βdocker logs proxy -...
Show more (64 lines)
Tool Result (ID: toolu_016DojYQCR2hACNVRgd8zZrW)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
480β
481β# Check proxy logs
482βdocker logs proxy --tail 100
483β
484β# Verify credentials
485βls -la credentials/
486β```
487β
488β## Security Considerations
489β
490β### β οΈ CRITICAL: Dashboard Authentication
491β
492β**Never deploy the dashboard without setting `DASHBOARD_API_KEY`!**
493β
494βWhen `DASHBOARD_API_KEY` is not set, the dashboard runs in "read-only mode" with NO authentication, exposing:
495β- All conversation histories
496β- Token usage and costs
497β- Account information
498β- AI analysis results
499β- Potentially sensitive customer data
500β
501β**Production Security Checklist:**
502β
503β```bash
504β# 1. ALWAYS set DASHBOARD_API_KEY (minimum 32 characters)
505βexport DASHBOARD_API_KEY=$(openssl rand -base64 32)
506β
507β# 2. Verify it's set before deployment
508βif [ -z "$DASHBOARD_API_KEY" ]; then
509β echo "ERROR: DASHBOARD_API_KEY not set!"
510β exit 1
511βfi
512β
513β# 3. Never expose dashboard port directly to internet
514β# Use reverse proxy with additional authentication
515β# Block port 3001 at firewall level
516β
517β# 4. Test authentication is working
518βcurl -I http://localhost:3001/dashboard
519β# Should return 302 redirect to login
520β```
521β
522β### Network Security
523β
524β1. **Firewall Rules**:
525β - Only expose reverse proxy ports (80/443)
526β - Block direct access to service ports (3000/3001)
527β - Whitelist specific IPs if possible
528β
529β2. **Internal Network Only**:
530β ```bash
531β # Docker: Use internal network
532β docker run --network internal ...
533β
534β # Or bind to localhost only
535β docker run -p 127.0.0.1:3001:3001 ...
536β ```
537β
538β3. **Additional Authentication Layer**:
539β - Consider basic auth at reverse proxy level
540β - Use VPN for dashboard access
541β - Implement IP whitelisting
542β
543βSee the [Security Guide](../security.md) for comprehensive security information.
544β
Show less
Tool Use: Edit (ID: toolu_016DojYQCR2hACNVRgd8zZrW)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md",
"new_string": "# Verify credentials\nls -la credentials/\n```\n\n## Security Considerations\n\n### β οΈ CRITICAL: Dashboard Authent...
Show more (4 lines)
Tool Use: Edit (ID: toolu_016DojYQCR2hACNVRgd8zZrW)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md",
"new_string": "# Verify credentials\nls -la credentials/\n```\n\n## Security Considerations\n\n### β οΈ CRITICAL: Dashboard Authentication\n\n**Never deploy the dashboard without setting `DASHBOARD_API_KEY`!**\n\nWhen `DASHBOARD_API_KEY` is not set, the dashboard runs in \"read-only mode\" with NO authentication, exposing:\n- All conversation histories\n- Token usage and costs\n- Account information\n- AI analysis results\n- Potentially sensitive customer data\n\n**Production Security Checklist:**\n\n```bash\n# 1. ALWAYS set DASHBOARD_API_KEY (minimum 32 characters)\nexport DASHBOARD_API_KEY=$(openssl rand -base64 32)\n\n# 2. Verify it's set before deployment\nif [ -z \"$DASHBOARD_API_KEY\" ]; then\n echo \"ERROR: DASHBOARD_API_KEY not set!\"\n exit 1\nfi\n\n# 3. Never expose dashboard port directly to internet\n# Use reverse proxy with additional authentication\n# Block port 3001 at firewall level\n\n# 4. Test authentication is working\ncurl -I http://localhost:3001/dashboard\n# Should return 302 redirect to login\n```\n\n### Network Security\n\n1. **Firewall Rules**:\n - Only expose reverse proxy ports (80/443)\n - Block direct access to service ports (3000/3001)\n - Whitelist specific IPs if possible\n\n2. **Internal Network Only**:\n ```bash\n # Docker: Use internal network\n docker run --network internal ...\n \n # Or bind to localhost only\n docker run -p 127.0.0.1:3001:3001 ...\n ```\n\n3. **Additional Authentication Layer**:\n - Consider basic auth at reverse proxy level\n - Use VPN for dashboard access\n - Implement IP whitelisting\n\nSee the [Security Guide](../security.md) for comprehensive security information.",
"old_string": "# Verify credentials\nls -la credentials/\n```"
}
Show less
Tool Result (ID: toolu_01MCckXXrPRkHvCtF4dov5Qr)
docker service update --image claude-nexus-dashboard:new dashboard
Database Maintenance
# Vacuum and analyze
psql $DATABASE_URL -c "VACUUM ANALYZE;"
# Reindex for performance
psql $DATABASE_URL -c "REINDEX DATABASE claude_n...
Show more (41 lines)
Tool Result (ID: toolu_01MCckXXrPRkHvCtF4dov5Qr)
docker service update --image claude-nexus-dashboard:new dashboard
Database Maintenance
# Vacuum and analyze
psql $DATABASE_URL -c "VACUUM ANALYZE;"
# Reindex for performance
psql $DATABASE_URL -c "REINDEX DATABASE claude_nexus;"
Troubleshooting Production Issues
High Memory Usage
# Check memory usage
docker stats
# Limit container memory
docker run -m 1g claude-nexus-proxy
Slow Queries
# Enable slow query logging
SLOW_QUERY_THRESHOLD_MS=1000
# Check pg_stat_statements
SELECT query, mean_exec_time, calls
FROM pg_stat_statements
ORDER BY mean_exec_time DESC
LIMIT 10;
Connection Issues
# Test database connection
psql $DATABASE_URL -c "SELECT 1;"
# Check proxy logs
docker logs proxy --tail 100
# Verify credentials
ls -la credentials/
Show less
Let me check the end of the file to see where to add the security section:
Tool Use: Bash (ID: toolu_01MCckXXrPRkHvCtF4dov5Qr)
{
"command": "tail -50 /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md",
"description": "Check end of docker deplo...
Show more (3 lines)
Let me check the end of the file to see where to add the security section:
Tool Use: Bash (ID: toolu_01MCckXXrPRkHvCtF4dov5Qr)
{
"command": "tail -50 /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md",
"description": "Check end of docker deployment guide"
}
Show less
Tool Result (ID: toolu_01HXGLRArVQjfYemvZJ1iT1n)
200β proxy_set_header X-Real-IP $remote_addr;
201β proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
202β
203β # For streaming responses
204β proxy_buffering off;
205β proxy_cache o...
Show more (105 lines)
Tool Result (ID: toolu_01HXGLRArVQjfYemvZJ1iT1n)
200β proxy_set_header X-Real-IP $remote_addr;
201β proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
202β
203β # For streaming responses
204β proxy_buffering off;
205β proxy_cache off;
206β }
207β}
208β
209β# Dashboard
210βserver {
211β listen 443 ssl http2;
212β server_name dashboard.yourdomain.com;
213β
214β ssl_certificate /path/to/cert.pem;
215β ssl_certificate_key /path/to/key.pem;
216β
217β location / {
218β proxy_pass http://dashboard_backend;
219β proxy_http_version 1.1;
220β proxy_set_header Host $host;
221β proxy_set_header X-Real-IP $remote_addr;
222β }
223β
224β # SSE endpoint
225β location /sse {
226β proxy_pass http://dashboard_backend/sse;
227β proxy_http_version 1.1;
228β proxy_set_header Connection "";
229β proxy_buffering off;
230β proxy_cache off;
231β }
232β}
233β```
234β
235β#### Caddy Configuration
236β
237β```caddyfile
238βapi.yourdomain.com {
239β reverse_proxy localhost:3000 {
240β flush_interval -1
241β }
242β}
243β
244βdashboard.yourdomain.com {
245β reverse_proxy localhost:3001
246β}
247β```
248β
249β## Scaling
250β
251β### Horizontal Scaling
252β
253β1. **Proxy Service** - Stateless, scale freely:
254β
255β```bash
256β# Docker Swarm
257βdocker service scale proxy=5
258β
259β# Kubernetes
260βkubectl scale deployment proxy --replicas=5
261β```
262β
263β2. **Dashboard Service** - Also stateless:
264β
265β```bash
266βdocker service scale dashboard=3
267β```
268β
269β3. **Database** - Use read replicas for dashboard:
270β
271β```bash
272β# Primary for writes (proxy)
273βDATABASE_URL=postgresql://primary:5432/claude_nexus
274β
275β# Read replica for dashboard
276βDATABASE_URL=postgresql://replica:5432/claude_nexus
277β```
278β
279β### Performance Tuning
280β
281β1. **Connection Pooling**:
282β
283β```bash
284βDATABASE_URL=postgresql://...?pool_max=50&pool_idle_timeout=10000
285β```
286β
287β2. **Disable Non-Essential Features**:
288β
289β```bash
290βSTORAGE_ENABLED=false # If not needed
291βDEBUG=false
292βCOLLECT_TEST_SAMPLES=false
293β```
294β
295β3. **Optimize Dashboard**:
296β
297β```bash
298βDASHBOARD_CACHE_TTL=600 # 10-minute cache
299β```
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
<system-reminder>
The TodoWrite tool hasn't been used recently. If you're working on tasks that would benefit from tracking progress, consider using the TodoWrite tool to track progress. Only use it if it's relevant to the current work. This is just a gentle reminder - ignore if not applicable.
</system-reminder>
Show less
Let me also add a security section to this deployment guide:
Tool Use: Read (ID: toolu_01HXGLRArVQjfYemvZJ1iT1n)
{
"limit": 100,
"offset": 200,
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md"
}
Tool Result (ID: toolu_014kiuBb7L1r9zzBvYvJwa6M)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
45β -e DATABASE_URL=$DATABASE_URL \
46β -v $(pwd)/...
Show more (16 lines)
Tool Result (ID: toolu_014kiuBb7L1r9zzBvYvJwa6M)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
45β -e DATABASE_URL=$DATABASE_URL \
46β -v $(pwd)/credentials:/app/credentials:ro \
47β claude-nexus-proxy
48β
49β# Run dashboard
50β# β οΈ CRITICAL: Always set DASHBOARD_API_KEY to prevent unauthorized access
51βdocker run -d \
52β --name claude-dashboard \
53β -p 3001:3001 \
54β -e DATABASE_URL=$DATABASE_URL \
55β -e DASHBOARD_API_KEY=$DASHBOARD_API_KEY \
56β claude-nexus-dashboard
57β```
58β
59β### 2. Bare Metal with Bun
60β
Show less
Let me add security warnings to the docker deployment guide:
Tool Use: Edit (ID: toolu_014kiuBb7L1r9zzBvYvJwa6M)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md",
"new_string": "# Run dashboard\n# β οΈ CRITICAL: Always set DASH...
Show more (4 lines)
Let me add security warnings to the docker deployment guide:
Tool Use: Edit (ID: toolu_014kiuBb7L1r9zzBvYvJwa6M)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md",
"new_string": "# Run dashboard\n# β οΈ CRITICAL: Always set DASHBOARD_API_KEY to prevent unauthorized access\ndocker run -d \\\n --name claude-dashboard \\\n -p 3001:3001 \\\n -e DATABASE_URL=$DATABASE_URL \\\n -e DASHBOARD_API_KEY=$DASHBOARD_API_KEY \\\n claude-nexus-dashboard",
"old_string": "# Run dashboard\ndocker run -d \\\n --name claude-dashboard \\\n -p 3001:3001 \\\n -e DATABASE_URL=$DATABASE_URL \\\n -e DASHBOARD_API_KEY=$DASHBOARD_API_KEY \\\n claude-nexus-dashboard"
}
Show less
Tool Result (ID: toolu_016kDhK7y2ptAhwmtAjoFipU)
1β# Deployment Guide
2β
3βThis guide covers deploying Claude Nexus Proxy to production environments.
4β
5β## Deployment Options
6β
7β> **Note**: For AWS EC2 deployment with staging/production environments, s...
Show more (100 lines)
Tool Result (ID: toolu_016kDhK7y2ptAhwmtAjoFipU)
1β# Deployment Guide
2β
3βThis guide covers deploying Claude Nexus Proxy to production environments.
4β
5β## Deployment Options
6β
7β> **Note**: For AWS EC2 deployment with staging/production environments, see [AWS Infrastructure Guide](./aws-infrastructure.md).
8β
9β### 1. Docker (Recommended)
10β
11βThe project provides optimized Docker images for each service.
12β
13β#### Build Images
14β
15β```bash
16β# Build both images
17β./docker/build-images.sh
18β
19β# Or build individually
20βdocker build -f docker/proxy/Dockerfile -t claude-nexus-proxy .
21βdocker build -f docker/dashboard/Dockerfile -t claude-nexus-dashboard .
22β```
23β
24β#### Run with Docker Compose
25β
26β```bash
27β# Create .env file
28βcp .env.example .env
29β# Edit .env with production values
30β
31β# Start services
32βdocker-compose up -d
33β
34β# View logs
35βdocker-compose logs -f
36β```
37β
38β#### Run Standalone Containers
39β
40β```bash
41β# Run proxy
42βdocker run -d \
43β --name claude-proxy \
44β -p 3000:3000 \
45β -e DATABASE_URL=$DATABASE_URL \
46β -v $(pwd)/credentials:/app/credentials:ro \
47β claude-nexus-proxy
48β
49β# Run dashboard
50βdocker run -d \
51β --name claude-dashboard \
52β -p 3001:3001 \
53β -e DATABASE_URL=$DATABASE_URL \
54β -e DASHBOARD_API_KEY=$DASHBOARD_API_KEY \
55β claude-nexus-dashboard
56β```
57β
58β### 2. Bare Metal with Bun
59β
60β#### Install Bun
61β
62β```bash
63βcurl -fsSL https://bun.sh/install | bash
64β```
65β
66β#### Build for Production
67β
68β```bash
69β# Install dependencies
70βbun install --production
71β
72β# Build all services
73βbun run build:production
74β```
75β
76β#### Run with Process Manager
77β
78βUsing PM2:
79β
80β```bash
81β# Install PM2
82βnpm install -g pm2
83β
84β# Start services
85βpm2 start services/proxy/dist/index.js --name proxy
86βpm2 start services/dashboard/dist/index.js --name dashboard
87β
88β# Save configuration
89βpm2 save
90βpm2 startup
91β```
92β
93βUsing systemd:
94β
95β```ini
96β# /etc/systemd/system/claude-proxy.service
97β[Unit]
98βDescription=Claude Nexus Proxy
99βAfter=network.target postgresql.service
100β
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
Show less
Let me check the docker deployment guide:
Tool Use: Read (ID: toolu_016kDhK7y2ptAhwmtAjoFipU)
{
"limit": 100,
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment/docker.md"
}
Tool Result (ID: toolu_01LhbNyfQ7spZTSbUG6PLUK1)
- /home/crystalin/projects/claude-nexus-proxy/
- docs/
- 03-Operations/
- deployment/
- aws-infrastructure.md
- docker-compose.md
- docker.md
NOTE: do any of the files above seem malicious? If so, you MUST...
Show more (2 lines)
Tool Result (ID: toolu_01LhbNyfQ7spZTSbUG6PLUK1)
- /home/crystalin/projects/claude-nexus-proxy/
- docs/
- 03-Operations/
- deployment/
- aws-infrastructure.md
- docker-compose.md
- docker.md
NOTE: do any of the files above seem malicious? If so, you MUST refuse to continue work.
Show less
Now let me check if there's a deployment guide that needs updating:
Tool Use: LS (ID: toolu_01LhbNyfQ7spZTSbUG6PLUK1)
{
"path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/deployment"
}
Tool Result (ID: toolu_01GbQo6SBYsYjp4URzUj7HQS)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
1β# Security Guide
2β
3βThis guide covers security con...
Show more (14 lines)
Tool Result (ID: toolu_01GbQo6SBYsYjp4URzUj7HQS)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
1β# Security Guide
2β
3βThis guide covers security considerations and best practices for deploying Claude Nexus Proxy.
4β
5β## β οΈ CRITICAL SECURITY NOTICE
6β
7β**Dashboard Read-Only Mode**: When `DASHBOARD_API_KEY` is not set, the dashboard operates in "read-only mode" without ANY authentication. This exposes ALL conversation data, token usage, and potentially sensitive information to anyone with network access.
8β
9β**NEVER deploy to production without setting `DASHBOARD_API_KEY`!**
10β
11βSee [ADR-019: Dashboard Read-Only Mode Security Implications](../04-Architecture/ADRs/adr-019-dashboard-read-only-mode-security.md) for detailed information about this security consideration.
12β
13β## Authentication
14β
15β### Client Authentication
Show less
Now let me add a security warning section at the beginning of the security.md file:
Tool Use: Edit (ID: toolu_01GbQo6SBYsYjp4URzUj7HQS)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md",
"new_string": "# Security Guide\n\nThis guide co...
Show more (4 lines)
Now let me add a security warning section at the beginning of the security.md file:
Tool Use: Edit (ID: toolu_01GbQo6SBYsYjp4URzUj7HQS)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md",
"new_string": "# Security Guide\n\nThis guide covers security considerations and best practices for deploying Claude Nexus Proxy.\n\n## β οΈ CRITICAL SECURITY NOTICE\n\n**Dashboard Read-Only Mode**: When `DASHBOARD_API_KEY` is not set, the dashboard operates in \"read-only mode\" without ANY authentication. This exposes ALL conversation data, token usage, and potentially sensitive information to anyone with network access. \n\n**NEVER deploy to production without setting `DASHBOARD_API_KEY`!**\n\nSee [ADR-019: Dashboard Read-Only Mode Security Implications](../04-Architecture/ADRs/adr-019-dashboard-read-only-mode-security.md) for detailed information about this security consideration.",
"old_string": "# Security Guide\n\nThis guide covers security considerations and best practices for deploying Claude Nexus Proxy."
}
Show less
Tool Result (ID: toolu_0133S2yVqQcvhQ2kFNAWo82x)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
219β- [ ] Regular credential rotation
220β- [ ] Database backup...
Show more (42 lines)
Tool Result (ID: toolu_0133S2yVqQcvhQ2kFNAWo82x)
The file /home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
219β- [ ] Regular credential rotation
220β- [ ] Database backup encryption
221β- [ ] Security audit schedule
222β
223β## Common Vulnerabilities
224β
225β### 1. Exposed Dashboard (CRITICAL)
226β
227β**Risk**: Dashboard accessible without authentication exposes ALL conversation data
228β
229β**β οΈ CRITICAL SECURITY WARNING**:
230βWhen `DASHBOARD_API_KEY` is not set, the dashboard runs in "read-only mode" with NO authentication. This means:
231β- Anyone with network access can view ALL conversations
232β- All API requests and responses are visible
233β- Token usage, costs, and account information are exposed
234β- AI analysis results and insights are accessible
235β- This includes potentially sensitive customer data, API keys in conversations, and proprietary information
236β
237β**Impact**: Complete data exposure, privacy breach, potential compliance violations
238β
239β**Mitigation**:
240β
241β- **ALWAYS** set `DASHBOARD_API_KEY` in production
242β- Use strong, unique keys (minimum 32 characters)
243β- Restrict dashboard to internal network only
244β- Never expose dashboard port (3001) to the internet
245β- Consider using a reverse proxy with additional authentication
246β- For local development only, use read-only mode behind a firewall
247β
248β**Checking for Vulnerability**:
249β```bash
250β# If this returns empty, your dashboard is UNSECURED
251βecho $DASHBOARD_API_KEY
252β
253β# Check if dashboard is publicly accessible
254βcurl http://your-server:3001/dashboard
255β# If you see the dashboard without login, it's exposed
256β```
257β
258β### 2. Credential Leakage
259β
260β**Risk**: Credentials in logs or error messages
Show less
Now let me update the security.md file to add more detailed warnings about read-only mode:
Tool Use: Edit (ID: toolu_0133S2yVqQcvhQ2kFNAWo82x)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md",
"new_string": "## Common Vulnerabilities\...
Show more (4 lines)
Now let me update the security.md file to add more detailed warnings about read-only mode:
Tool Use: Edit (ID: toolu_0133S2yVqQcvhQ2kFNAWo82x)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md",
"new_string": "## Common Vulnerabilities\n\n### 1. Exposed Dashboard (CRITICAL)\n\n**Risk**: Dashboard accessible without authentication exposes ALL conversation data\n\n**β οΈ CRITICAL SECURITY WARNING**: \nWhen `DASHBOARD_API_KEY` is not set, the dashboard runs in \"read-only mode\" with NO authentication. This means:\n- Anyone with network access can view ALL conversations\n- All API requests and responses are visible\n- Token usage, costs, and account information are exposed\n- AI analysis results and insights are accessible\n- This includes potentially sensitive customer data, API keys in conversations, and proprietary information\n\n**Impact**: Complete data exposure, privacy breach, potential compliance violations\n\n**Mitigation**:\n\n- **ALWAYS** set `DASHBOARD_API_KEY` in production\n- Use strong, unique keys (minimum 32 characters)\n- Restrict dashboard to internal network only\n- Never expose dashboard port (3001) to the internet\n- Consider using a reverse proxy with additional authentication\n- For local development only, use read-only mode behind a firewall\n\n**Checking for Vulnerability**:\n```bash\n# If this returns empty, your dashboard is UNSECURED\necho $DASHBOARD_API_KEY\n\n# Check if dashboard is publicly accessible\ncurl http://your-server:3001/dashboard\n# If you see the dashboard without login, it's exposed\n```",
"old_string": "## Common Vulnerabilities\n\n### 1. Exposed Dashboard\n\n**Risk**: Dashboard accessible without authentication\n\n**Mitigation**:\n\n- Always set `DASHBOARD_API_KEY`\n- Use strong, unique keys\n- Restrict dashboard to internal network"
}
Show less
Tool Result (ID: toolu_01RSwaFB2Q4dc4Ww4QArUvCF)
The file /home/crystalin/projects/claude-nexus-proxy/README.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
140β "messages": [{"role": "user", "content": "Hello!"}]
141β }'
142β```
1...
Show more (18 lines)
Tool Result (ID: toolu_01RSwaFB2Q4dc4Ww4QArUvCF)
The file /home/crystalin/projects/claude-nexus-proxy/README.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
140β "messages": [{"role": "user", "content": "Hello!"}]
141β }'
142β```
143β
144β### Dashboard
145β
146βAccess the dashboard at `http://localhost:3001` with your `DASHBOARD_API_KEY`.
147β
148β**β οΈ Security Warning**: If `DASHBOARD_API_KEY` is not set, the dashboard runs in read-only mode without any authentication, exposing all conversation data. This should NEVER be used in production. See the [Security Guide](docs/03-Operations/security.md) for details.
149β
150βFeatures:
151β
152β- Real-time request monitoring
153β- Conversation visualization with branching
154β- Token usage analytics
<system-reminder>
The TodoWrite tool hasn't been used recently. If you're working on tasks that would benefit from tracking progress, consider using the TodoWrite tool to track progress. Only use it if it's relevant to the current work. This is just a gentle reminder - ignore if not applicable.
</system-reminder>
Show less
Tool Use: Edit (ID: toolu_01RSwaFB2Q4dc4Ww4QArUvCF)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/README.md",
"new_string": "### Dashboard\n\nAccess the dashboard at `http://localhost:3001` with your `DASHBOARD_API_KEY`.\n\n**β οΈ Security Warning**: If `DASHBOARD_API_KE...
Show more (4 lines)
Tool Use: Edit (ID: toolu_01RSwaFB2Q4dc4Ww4QArUvCF)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/README.md",
"new_string": "### Dashboard\n\nAccess the dashboard at `http://localhost:3001` with your `DASHBOARD_API_KEY`.\n\n**β οΈ Security Warning**: If `DASHBOARD_API_KEY` is not set, the dashboard runs in read-only mode without any authentication, exposing all conversation data. This should NEVER be used in production. See the [Security Guide](docs/03-Operations/security.md) for details.\n\nFeatures:",
"old_string": "### Dashboard\n\nAccess the dashboard at `http://localhost:3001` with your `DASHBOARD_API_KEY`.\n\nFeatures:"
}
Show less
Tool Result (ID: toolu_01JujrDtNGZyzekfcRLkFiBS)
The file /home/crystalin/projects/claude-nexus-proxy/README.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
91β```bash
92β# Database
93βDATABASE_URL=postgresql://user:password@localhost:...
Show more (12 lines)
Tool Result (ID: toolu_01JujrDtNGZyzekfcRLkFiBS)
The file /home/crystalin/projects/claude-nexus-proxy/README.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
91β```bash
92β# Database
93βDATABASE_URL=postgresql://user:password@localhost:5432/claude_nexus
94β
95β# Dashboard Authentication
96β# β οΈ CRITICAL SECURITY WARNING: Without this key, the dashboard runs in read-only mode
97β# with NO authentication, exposing ALL conversation data to anyone with network access!
98β# NEVER deploy to production without setting this!
99βDASHBOARD_API_KEY=your-secure-key
100β
101β# Optional Features
102βSTORAGE_ENABLED=true
103βDEBUG=false
Show less
Now let me update the main README.md to add security warnings:
Tool Use: Edit (ID: toolu_01JujrDtNGZyzekfcRLkFiBS)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/README.md",
"new_string": "# Dashboard Authentication\n# β οΈ CRITICAL SECURITY WARNING: Without this ke...
Show more (4 lines)
Now let me update the main README.md to add security warnings:
Tool Use: Edit (ID: toolu_01JujrDtNGZyzekfcRLkFiBS)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/README.md",
"new_string": "# Dashboard Authentication\n# β οΈ CRITICAL SECURITY WARNING: Without this key, the dashboard runs in read-only mode\n# with NO authentication, exposing ALL conversation data to anyone with network access!\n# NEVER deploy to production without setting this!\nDASHBOARD_API_KEY=your-secure-key",
"old_string": "# Dashboard Authentication\nDASHBOARD_API_KEY=your-secure-key"
}
Show less
Tool Result (ID: toolu_01RLhWdvZurA7rx7WbyAaGbk)
The file /home/crystalin/projects/claude-nexus-proxy/CLAUDE.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
369β- Failed query errors with details
370β
371β## Environment Variables
372β
...
Show more (9 lines)
Tool Result (ID: toolu_01RLhWdvZurA7rx7WbyAaGbk)
The file /home/crystalin/projects/claude-nexus-proxy/CLAUDE.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
369β- Failed query errors with details
370β
371β## Environment Variables
372β
373β**Essential:**
374β
375β- `DATABASE_URL` - PostgreSQL connection
376β- `DASHBOARD_API_KEY` - Dashboard authentication (β οΈ **CRITICAL**: Without this, dashboard runs in read-only mode with NO authentication)
377β
378β**Optional:**
379β
380β- `DEBUG` - Enable debug logging
Show less
Tool Use: Edit (ID: toolu_01RLhWdvZurA7rx7WbyAaGbk)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/CLAUDE.md",
"new_string": "**Essential:**\n\n- `DATABASE_URL` - PostgreSQL connection\n- `DASHBOARD_API_KEY` - Dashboard authentication (β οΈ **CRITICAL**: Without this, das...
Show more (4 lines)
Tool Use: Edit (ID: toolu_01RLhWdvZurA7rx7WbyAaGbk)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/CLAUDE.md",
"new_string": "**Essential:**\n\n- `DATABASE_URL` - PostgreSQL connection\n- `DASHBOARD_API_KEY` - Dashboard authentication (β οΈ **CRITICAL**: Without this, dashboard runs in read-only mode with NO authentication)",
"old_string": "**Essential:**\n\n- `DATABASE_URL` - PostgreSQL connection\n- `DASHBOARD_API_KEY` - Dashboard authentication"
}
Show less
Tool Result (ID: toolu_01USgMjd1yMUgWj4yqsjB6QN)
The file /home/crystalin/projects/claude-nexus-proxy/CLAUDE.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
49β- Request/response storage
50β- Slack notifications
51β- AI-powered convers...
Show more (14 lines)
Tool Result (ID: toolu_01USgMjd1yMUgWj4yqsjB6QN)
The file /home/crystalin/projects/claude-nexus-proxy/CLAUDE.md has been updated. Here's the result of running `cat -n` on a snippet of the edited file:
49β- Request/response storage
50β- Slack notifications
51β- AI-powered conversation analysis (Phase 2 - Prompt Engineering with full env var support)
52β
53β**Dashboard Service** (`services/dashboard/`)
54β
55β- Monitoring UI
56β- Analytics and usage charts
57β- Request history browser
58β- SSE for live updates
59β- **β οΈ SECURITY WARNING**: Read-only mode (when `DASHBOARD_API_KEY` is not set) exposes all data without authentication. See [ADR-019](docs/04-Architecture/ADRs/adr-019-dashboard-read-only-mode-security.md)
60β
61β## Development
62β
63β```bash
Show less
Now let me update the CLAUDE.md file to include security warnings:
Tool Use: Edit (ID: toolu_01USgMjd1yMUgWj4yqsjB6QN)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/CLAUDE.md",
"new_string": "**Dashboard Service** (`services/dashboard/`)\n\n- Monitoring UI\n- Ana...
Show more (4 lines)
Now let me update the CLAUDE.md file to include security warnings:
Tool Use: Edit (ID: toolu_01USgMjd1yMUgWj4yqsjB6QN)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/CLAUDE.md",
"new_string": "**Dashboard Service** (`services/dashboard/`)\n\n- Monitoring UI\n- Analytics and usage charts\n- Request history browser\n- SSE for live updates\n- **β οΈ SECURITY WARNING**: Read-only mode (when `DASHBOARD_API_KEY` is not set) exposes all data without authentication. See [ADR-019](docs/04-Architecture/ADRs/adr-019-dashboard-read-only-mode-security.md)",
"old_string": "**Dashboard Service** (`services/dashboard/`)\n\n- Monitoring UI\n- Analytics and usage charts\n- Request history browser\n- SSE for live updates"
}
Show less
Tool Result (ID: toolu_01MuaQ7JmWcptGbBDZokeSmw)
File created successfully at: /home/crystalin/projects/claude-nexus-proxy/docs/04-Architecture/ADRs/adr-019-dashboard-read-only-mode-security.md
Now I'll create a comprehensive update to the documentation reflecting the security findings about read-only mode. Let me start with creating an ADR documenting this decision:
Tool Use: Write (ID: toolu_01MuaQ7JmWcptGbBDZokeSmw)
{
"content": "# ADR-019: Dashboard Read-Only Mode ...
Show more (4 lines)
Now I'll create a comprehensive update to the documentation reflecting the security findings about read-only mode. Let me start with creating an ADR documenting this decision:
Tool Use: Write (ID: toolu_01MuaQ7JmWcptGbBDZokeSmw)
{
"content": "# ADR-019: Dashboard Read-Only Mode Security Implications\n\n## Status\n\nAccepted\n\n## Context\n\nThe Claude Nexus Proxy dashboard was modified to support a \"read-only mode\" that allows access without authentication when `DASHBOARD_API_KEY` is not set. This was implemented to simplify development and quick deployments, but it introduces significant security concerns that need to be documented and addressed.\n\n### Current Implementation\n\nWhen `DASHBOARD_API_KEY` is not set in the environment:\n- The dashboard operates in \"read-only mode\" (`isReadOnly = true`)\n- All authentication checks are bypassed\n- Anyone with network access to the dashboard can view all data\n- This includes sensitive information such as:\n - All API requests and responses\n - Conversation histories with potentially sensitive content\n - Token usage statistics and costs\n - Account identifiers and usage patterns\n - AI analysis results and insights\n\n## Decision Drivers\n\n- **Developer Experience**: Need for quick local development without authentication setup\n- **Security**: Protecting sensitive conversation data and usage information\n- **Deployment Safety**: Preventing accidental exposure of data in production\n- **Transparency**: Clear communication about security implications\n- **Backward Compatibility**: Supporting existing deployments that rely on read-only mode\n\n## Considered Options\n\n1. **Remove Read-Only Mode Entirely**\n - Description: Require `DASHBOARD_API_KEY` in all cases\n - Pros: \n - Eliminates security risk completely\n - Forces secure configuration\n - Simpler security model\n - Cons: \n - Breaks existing deployments\n - Complicates local development\n - More setup friction\n\n2. **Keep Read-Only Mode with Clear Warnings**\n - Description: Maintain current behavior but add prominent security warnings\n - Pros:\n - Preserves backward compatibility\n - Maintains developer convenience\n - Clear about security implications\n - Cons:\n - Security risk remains\n - Users may ignore warnings\n - Potential for misconfiguration\n\n3. **Read-Only Mode for Local Development Only**\n - Description: Enable read-only mode only when explicitly running in development mode\n - Pros:\n - Balances security and convenience\n - Safe by default in production\n - Developer-friendly\n - Cons:\n - Requires additional configuration\n - May confuse users about when auth is required\n\n4. **Implement IP-Based Restrictions for Read-Only Mode**\n - Description: Allow read-only mode but restrict to localhost/private IPs\n - Pros:\n - Safer than unrestricted access\n - Still convenient for local development\n - Cons:\n - Can be bypassed with proxies\n - Complex to implement correctly\n - False sense of security\n\n## Decision\n\nWe will **keep read-only mode with clear warnings** (Option 2) for now, but with the following immediate actions:\n\n1. Add prominent security warnings in all documentation\n2. Display security warnings in the dashboard UI when in read-only mode\n3. Log warnings at startup when read-only mode is active\n4. Plan for deprecation in a future major version\n\n### Implementation Details\n\n1. **Documentation Updates**:\n - Add security warnings to README.md\n - Update CLAUDE.md with security implications\n - Enhance security.md with detailed warnings\n - Add warnings to deployment guides\n\n2. **UI Warnings**:\n ```typescript\n // Display banner when in read-only mode\n if (isReadOnly) {\n showWarningBanner('Dashboard is in read-only mode without authentication. Do not use in production!')\n }\n ```\n\n3. **Startup Warnings**:\n ```typescript\n if (!process.env.DASHBOARD_API_KEY) {\n console.warn('β οΈ WARNING: Dashboard running in READ-ONLY MODE without authentication!')\n console.warn('β οΈ This exposes all conversation data to anyone with network access.')\n console.warn('β οΈ Set DASHBOARD_API_KEY environment variable to enable authentication.')\n }\n ```\n\n## Consequences\n\n### Positive\n\n- Maintains backward compatibility\n- Preserves developer convenience for local development\n- Clear communication reduces risk of accidental exposure\n- Provides migration path for existing users\n\n### Negative\n\n- Security vulnerability remains until deprecated\n- Risk of users ignoring warnings\n- Potential for data exposure if deployed incorrectly\n- Technical debt that needs future resolution\n\n### Security Implications\n\n**Critical**: Running the dashboard without `DASHBOARD_API_KEY` exposes:\n- All conversation histories\n- Token usage and costs\n- Account information\n- AI analysis results\n- Request/response payloads\n\nThis mode should **NEVER** be used in production or any environment accessible from the internet.\n\n## Future Recommendations\n\n1. **Phase 1** (Current): Add warnings and documentation\n2. **Phase 2** (Next Minor Version): Add deprecation warnings\n3. **Phase 3** (Next Major Version): Remove read-only mode or restrict to explicit development mode\n4. **Alternative**: Implement a separate \"demo mode\" with synthetic data for testing\n\n## References\n\n- [Security Guide](../../03-Operations/security.md)\n- [Dashboard Architecture (ADR-009)](./adr-009-dashboard-architecture.md)\n- Original PR: feat: add read-only mode support for dashboard without API key",
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/04-Architecture/ADRs/adr-019-dashboard-read-only-mode-security.md"
}
Show less
Tool Result (ID: toolu_017RD3eqxVioGY64A7FkT2dR)
1β# Security Guide
2β
3βThis guide covers security considerations and best practices for deploying Claude Nexus Proxy.
4β
5β## Authentication
6β
7β### Client Authentication
8β
9βThe proxy supports ...
Show more (303 lines)
Tool Result (ID: toolu_017RD3eqxVioGY64A7FkT2dR)
1β# Security Guide
2β
3βThis guide covers security considerations and best practices for deploying Claude Nexus Proxy.
4β
5β## Authentication
6β
7β### Client Authentication
8β
9βThe proxy supports multiple authentication layers:
10β
11β1. **Client API Keys** - For authenticating clients to the proxy
12β2. **Claude API Keys** - For authenticating the proxy to Claude
13β3. **OAuth Tokens** - Alternative to API keys with auto-refresh
14β
15β#### Client Authentication Setup
16β
17β```bash
18β# Generate secure client API key
19βbun run auth:generate-key
20β# Output: cnp_live_1a2b3c4d5e6f...
21β
22β# Add to domain credentials
23β{
24β "client_api_key": "cnp_live_1a2b3c4d5e6f..."
25β}
26β```
27β
28βClients must include this key in requests:
29β
30β```bash
31βcurl -H "Authorization: Bearer cnp_live_..." http://proxy/v1/messages
32β```
33β
34β#### Disabling Client Auth (Development Only)
35β
36β```bash
37βENABLE_CLIENT_AUTH=false # NOT recommended for production
38β```
39β
40β### OAuth Implementation
41β
42βOAuth tokens are automatically refreshed before expiry:
43β
44β```json
45β{
46β "type": "oauth",
47β "access_token": "...",
48β "refresh_token": "...",
49β "expires_at": "2024-12-31T23:59:59Z"
50β}
51β```
52β
53βThe proxy adds required headers:
54β
55β```
56βanthropic-beta: oauth-2025-04-20
57β```
58β
59β## Credential Management
60β
61β### Storage Security
62β
63β1. **File Permissions** - Credential files should be readable only by the proxy user:
64β
65β```bash
66βchmod 600 credentials/*.json
67βchown proxy-user:proxy-user credentials/*.json
68β```
69β
70β2. **Directory Security**:
71β
72β```bash
73βchmod 700 credentials/
74β```
75β
76β3. **Encryption at Rest** - Consider encrypting the credentials directory
77β
78β### Credential Rotation
79β
80βBest practices for key rotation:
81β
82β1. Generate new keys regularly
83β2. Update credentials without downtime:
84β
85β```bash
86β# Update credential file - proxy reloads automatically
87βecho '{"client_api_key": "new_key"}' > credentials/domain.json
88β```
89β
90β3. Monitor old key usage before removal
91β
92β## Data Protection
93β
94β### Sensitive Data Masking
95β
96βDebug logs automatically mask:
97β
98β- API keys: `sk-ant-****`
99β- Bearer tokens: `Bearer ****`
100β- OAuth tokens: `token-****`
101β
102β### Request/Response Storage
103β
104βWhen `STORAGE_ENABLED=true`:
105β
106β- Request bodies are stored in PostgreSQL
107β- Consider encrypting sensitive fields
108β- Implement data retention policies
109β
110β### Database Security
111β
112β```sql
113β-- Restrict database access
114βREVOKE ALL ON DATABASE claude_nexus FROM PUBLIC;
115βGRANT CONNECT ON DATABASE claude_nexus TO proxy_user;
116βGRANT SELECT, INSERT, UPDATE ON ALL TABLES TO proxy_user;
117β
118β-- Use SSL connections
119βDATABASE_URL=postgresql://user:pass@host:5432/db?sslmode=require
120β```
121β
122β## Network Security
123β
124β### TLS/SSL Configuration
125β
126β1. **Proxy Behind Load Balancer**:
127β
128β```nginx
129βupstream proxy {
130β server localhost:3000;
131β}
132β
133βserver {
134β listen 443 ssl;
135β ssl_certificate /path/to/cert.pem;
136β ssl_certificate_key /path/to/key.pem;
137β
138β location / {
139β proxy_pass http://proxy;
140β proxy_set_header X-Real-IP $remote_addr;
141β }
142β}
143β```
144β
145β2. **Direct TLS** (using a reverse proxy):
146β
147β- Terminate TLS at nginx/caddy
148β- Keep proxy on localhost only
149β
150β### IP Whitelisting
151β
152βRestrict access by IP:
153β
154β```nginx
155βlocation / {
156β allow 10.0.0.0/8;
157β allow 192.168.1.0/24;
158β deny all;
159β proxy_pass http://proxy;
160β}
161β```
162β
163β## Audit and Monitoring
164β
165β### Access Logging
166β
167βThe proxy logs all requests with:
168β
169β- Timestamp
170β- Domain
171β- Request ID
172β- IP address
173β- Response status
174β
175β### Security Monitoring
176β
177β1. **Failed Authentication Attempts**:
178β
179β```sql
180βSELECT COUNT(*), ip_address, domain
181βFROM api_requests
182βWHERE response_status = 401
183βGROUP BY ip_address, domain
184βHAVING COUNT(*) > 10;
185β```
186β
187β2. **Unusual Usage Patterns**:
188β
189β```sql
190β-- Detect token usage spikes
191βSELECT domain, DATE(timestamp), SUM(total_tokens)
192βFROM api_requests
193βGROUP BY domain, DATE(timestamp)
194βHAVING SUM(total_tokens) > average_daily_usage * 2;
195β```
196β
197β3. **Slack Alerts**:
198β
199β```bash
200βSLACK_WEBHOOK_URL=https://hooks.slack.com/...
201β```
202β
203β## Security Checklist
204β
205β### Pre-Deployment
206β
207β- [ ] Generate strong client API keys
208β- [ ] Set secure `DASHBOARD_API_KEY`
209β- [ ] Configure TLS/SSL
210β- [ ] Set appropriate file permissions
211β- [ ] Enable database SSL
212β- [ ] Review firewall rules
213β
214β### Post-Deployment
215β
216β- [ ] Monitor authentication failures
217β- [ ] Set up log aggregation
218β- [ ] Configure alerts for anomalies
219β- [ ] Regular credential rotation
220β- [ ] Database backup encryption
221β- [ ] Security audit schedule
222β
223β## Common Vulnerabilities
224β
225β### 1. Exposed Dashboard
226β
227β**Risk**: Dashboard accessible without authentication
228β
229β**Mitigation**:
230β
231β- Always set `DASHBOARD_API_KEY`
232β- Use strong, unique keys
233β- Restrict dashboard to internal network
234β
235β### 2. Credential Leakage
236β
237β**Risk**: Credentials in logs or error messages
238β
239β**Mitigation**:
240β
241β- Enable log masking
242β- Review error handling
243β- Avoid logging request bodies
244β
245β### 3. Database Injection
246β
247β**Risk**: SQL injection through user input
248β
249β**Mitigation**:
250β
251β- Proxy uses parameterized queries
252β- No user input in SQL construction
253β- Regular dependency updates
254β
255β## Incident Response
256β
257β### Suspected Breach
258β
259β1. **Immediate Actions**:
260β
261β```bash
262β# Rotate all keys
263βbun run auth:generate-key
264β
265β# Check access logs
266βSELECT * FROM api_requests
267βWHERE timestamp > 'suspected_breach_time'
268βORDER BY timestamp;
269β```
270β
271β2. **Investigation**:
272β
273β- Review authentication logs
274β- Check for unusual patterns
275β- Analyze token usage
276β
277β3. **Recovery**:
278β
279β- Rotate all credentials
280β- Update client configurations
281β- Monitor for continued activity
282β
283β## Security Updates
284β
285βStay informed about security updates:
286β
287β1. Watch the repository for security advisories
288β2. Update dependencies regularly:
289β
290β```bash
291βbun update
292β```
293β
294β3. Monitor Claude API security announcements
295β
296β## Compliance
297β
298βFor regulatory compliance:
299β
300β1. **Data Residency** - Deploy in appropriate regions
301β2. **Audit Trails** - Enable comprehensive logging
302β3. **Encryption** - Use TLS and encrypt at rest
303β4. **Access Control** - Implement principle of least privilege
304β5. **Data Retention** - Configure appropriate retention policies
305β
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
Show less
Let me check the security documentation:
Tool Use: Read (ID: toolu_017RD3eqxVioGY64A7FkT2dR)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/03-Operations/security.md"
}
Tool Result (ID: toolu_01Qcww7xz9Sx7rMwah4JZ92j)
1β# ADR-XXX: [Short Title]
2β
3β## Status
4β
5β[Proposed | Accepted | Deprecated | Superseded]
6β
7β## Context
8β
9β[Describe the context and problem statement. What is the issue that we're seeing ...
Show more (48 lines)
Tool Result (ID: toolu_01Qcww7xz9Sx7rMwah4JZ92j)
1β# ADR-XXX: [Short Title]
2β
3β## Status
4β
5β[Proposed | Accepted | Deprecated | Superseded]
6β
7β## Context
8β
9β[Describe the context and problem statement. What is the issue that we're seeing that is motivating this decision or change? Include any relevant background information, constraints, and forces at play.]
10β
11β## Decision Drivers
12β
13β- [Driver 1: e.g., Performance requirements]
14β- [Driver 2: e.g., Security concerns]
15β- [Driver 3: e.g., Developer experience]
16β- [Driver 4: e.g., Maintenance burden]
17β
18β## Considered Options
19β
20β1. **Option 1: [Name]**
21β - Description: [Brief description]
22β - Pros: [List of advantages]
23β - Cons: [List of disadvantages]
24β
25β2. **Option 2: [Name]**
26β - Description: [Brief description]
27β - Pros: [List of advantages]
28β - Cons: [List of disadvantages]
29β
30β3. **Option 3: [Name]**
31β - Description: [Brief description]
32β - Pros: [List of advantages]
33β - Cons: [List of disadvantages]
34β
35β## Decision
36β
37β[Describe the decision that was made. What is the change that we're proposing and/or doing? Be specific and actionable.]
38β
39β### Implementation Details
40β
41β[Optional: Include specific implementation details, code examples, or diagrams if helpful]
42β
43β```typescript
44β// Example code if relevant
45β```
46β
47β## Consequences
48β
49β### Positive
50β
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
Show less
Let me check an existing ADR to understand the format:
Tool Use: Read (ID: toolu_01Qcww7xz9Sx7rMwah4JZ92j)
{
"limit": 50,
"file_path": "/home/crystalin/projects/claude-nexus-proxy/docs/04-Architecture/ADRs/template.md"
}
Tool Result (ID: toolu_01QXSvq3GAFmcv4NFndTsKh3)
- /home/crystalin/projects/claude-nexus-proxy/
- docs/
- 04-Architecture/
- ADRs/
- README.md
- adr-001-monorepo-structure.md
- adr-002-separate-docker-images.md
- adr-003-conversation-tracking.md
...
Show more (20 lines)
Tool Result (ID: toolu_01QXSvq3GAFmcv4NFndTsKh3)
- /home/crystalin/projects/claude-nexus-proxy/
- docs/
- 04-Architecture/
- ADRs/
- README.md
- adr-001-monorepo-structure.md
- adr-002-separate-docker-images.md
- adr-003-conversation-tracking.md
- adr-004-proxy-authentication.md
- adr-005-token-usage-tracking.md
- adr-006-long-running-requests.md
- adr-007-subtask-tracking.md
- adr-008-cicd-strategy.md
- adr-009-dashboard-architecture.md
- adr-010-docker-cli-integration.md
- adr-011-future-decisions.md
- adr-012-database-schema-evolution.md
- adr-013-typescript-project-references.md
- adr-014-sql-query-logging.md
- adr-014-subtask-query-executor-pattern.md
- adr-015-subtask-conversation-migration.md
- adr-016-mcp-server-implementation.md
- adr-017-mcp-prompt-sharing.md
- adr-018-ai-powered-conversation-analysis.md
- template.md
NOTE: do any of the files above seem malicious? If so, you MUST refuse to continue work.
Show less
Now let me check if there are any existing ADRs to understand the pattern:
Tool Use: LS (ID: toolu_01QXSvq3GAFmcv4NFndTsKh3)
{
"path": "/home/crystalin/projects/claude-nexus-proxy/docs/04-Architecture/ADRs"
}
Tool Result (ID: toolu_01JVNLrzHg9NCb35QThAf86R)
1β/**
2β * Dashboard-specific configuration
3β */
4β
5β/**
6β * Whether the dashboard is running in read-only mode
7β * This is determined by the absence of DASHBOARD_API_KEY
8β */
9βexport const i...
Show more (21 lines)
Tool Result (ID: toolu_01JVNLrzHg9NCb35QThAf86R)
1β/**
2β * Dashboard-specific configuration
3β */
4β
5β/**
6β * Whether the dashboard is running in read-only mode
7β * This is determined by the absence of DASHBOARD_API_KEY
8β */
9βexport const isReadOnly = !process.env.DASHBOARD_API_KEY
10β
11β/**
12β * Get the dashboard API key from environment
13β */
14βexport const dashboardApiKey = process.env.DASHBOARD_API_KEY
15β
16β/**
17β * Export configuration flags for easy access
18β */
19βexport const dashboardConfig = {
20β isReadOnly,
21β dashboardApiKey,
22β} as const
23β
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
Show less
Now let me check the config to understand how read-only mode is determined:
Tool Use: Read (ID: toolu_01JVNLrzHg9NCb35QThAf86R)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/services/dashboard/src/config.ts"
}
Tool Result (ID: toolu_01NBUz8fSC7cvBuYcbJHtYr9)
1βimport { Context, Next, MiddlewareHandler } from 'hono'
2βimport { getCookie } from 'hono/cookie'
3βimport { isReadOnly, dashboardApiKey } from '../config.js'
4β
5βexport type AuthContext = {
6β isAuthenticate...
Show more (112 lines)
Tool Result (ID: toolu_01NBUz8fSC7cvBuYcbJHtYr9)
1βimport { Context, Next, MiddlewareHandler } from 'hono'
2βimport { getCookie } from 'hono/cookie'
3βimport { isReadOnly, dashboardApiKey } from '../config.js'
4β
5βexport type AuthContext = {
6β isAuthenticated: boolean
7β isReadOnly: boolean
8β}
9β
10β/**
11β * Dashboard authentication middleware
12β * Protects dashboard routes with API key authentication
13β * Supports read-only mode when DASHBOARD_API_KEY is not set
14β */
15βexport const dashboardAuth: MiddlewareHandler<{ Variables: { auth: AuthContext } }> = async (
16β c,
17β next
18β) => {
19β // Skip auth for login page
20β if (
21β c.req.path === '/dashboard/login' ||
22β c.req.path === '/dashboard/login/' ||
23β c.req.path === '/login' ||
24β c.req.path === '/login/'
25β ) {
26β return next()
27β }
28β
29β // Set read-only mode in context
30β c.set('auth', {
31β isAuthenticated: false,
32β isReadOnly: isReadOnly,
33β })
34β
35β // If in read-only mode, allow access without authentication
36β if (isReadOnly) {
37β return next()
38β }
39β
40β // Check for dashboard API key in environment
41β if (!dashboardApiKey) {
42β // This should not happen given the isReadOnly check above, but keep for safety
43β return c.html(
44β `
45β <div style="text-align: center; padding: 50px; font-family: sans-serif;">
46β <h1>Dashboard Not Configured</h1>
47β <p>Please set DASHBOARD_API_KEY environment variable to enable the dashboard.</p>
48β </div>
49β `,
50β 503
51β )
52β }
53β
54β // Check cookie authentication
55β const authCookie = getCookie(c, 'dashboard_auth')
56β if (authCookie === dashboardApiKey) {
57β c.set('auth', {
58β isAuthenticated: true,
59β isReadOnly: false,
60β })
61β return next()
62β }
63β
64β // Check header authentication (for API calls)
65β const headerKey = c.req.header('X-Dashboard-Key')
66β if (headerKey === dashboardApiKey) {
67β c.set('auth', {
68β isAuthenticated: true,
69β isReadOnly: false,
70β })
71β return next()
72β }
73β
74β // For SSE endpoints, check if user has auth cookie (browsers send cookies with EventSource)
75β if (c.req.path.includes('/sse') && authCookie) {
76β // Even if cookie doesn't match, let it through if it exists
77β // The SSE handler can do additional validation
78β return next()
79β }
80β
81β // Redirect to login for HTML requests
82β const acceptHeader = c.req.header('Accept') || ''
83β if (acceptHeader.includes('text/html')) {
84β return c.redirect('/dashboard/login')
85β }
86β
87β // Return 401 for API requests
88β return c.json({ error: 'Unauthorized' }, 401)
89β}
90β
91β/**
92β * Optional: Domain-scoped authentication
93β * Allows restricting dashboard access to specific domains
94β */
95βexport const domainScopedAuth = async (c: Context, next: Next) => {
96β // Get authenticated domain from context
97β const authenticatedDomain = c.get('authenticatedDomain')
98β
99β // Get requested domain from query params
100β const requestedDomain = c.req.query('domain')
101β
102β // If a specific domain is requested, verify access
103β if (requestedDomain && authenticatedDomain !== 'admin') {
104β if (authenticatedDomain !== requestedDomain) {
105β return c.json({ error: 'Access denied to this domain' }, 403)
106β }
107β }
108β
109β return next()
110β}
111β
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
Show less
Let me check the dashboard's security implementation:
Tool Use: Read (ID: toolu_01NBUz8fSC7cvBuYcbJHtYr9)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/services/dashboard/src/middleware/auth.ts"
}
Tool Result (ID: toolu_017X8Wj6VzwPFeZWQpfqi1Yo)
6abde7f fix: remove DASHBOARD_API_KEY requirement for read-only mode
ffa12ee fix: apply security improvements from code review
ab665ac feat: add read-only mode support for dashboard without API key
533a890 Repository cleanup: consolidate type...
Show more (8 lines)
Tool Result (ID: toolu_017X8Wj6VzwPFeZWQpfqi1Yo)
6abde7f fix: remove DASHBOARD_API_KEY requirement for read-only mode
ffa12ee fix: apply security improvements from code review
ab665ac feat: add read-only mode support for dashboard without API key
533a890 Repository cleanup: consolidate types and organize scripts (#90)
1106dfd feat: implement hourly usage dashboard for request tracking (#88)
200f4c0 fix: Fix MCP server GitHub sync issues and security vulnerabilities (#87)
346b8a0 feat: dark theme (#86)
809f743 fix: embed prompt assets at build time to fix production deployment (#85)
0d72237 fix migration
2f20e2c feat: implement API design for AI analysis feature (#80)
Show less
Now let me check the recent changes to understand the read-only mode implementation:
Tool Use: Bash (ID: toolu_017X8Wj6VzwPFeZWQpfqi1Yo)
{
"command": "git log --oneline -n 10",
"description": "Check recent commits for read-only mode changes"
}
Tool Result (ID: toolu_0189X5S9WSTiFjcioE3hcn6v)
1β# Claude Nexus Proxy
2β
3βA high-performance proxy for Claude API with comprehensive monitoring, conversation tracking, and dashboard visualization.
4β
5β## Features
6β
7β- π **High-Performance Proxy** - ...
Show more (294 lines)
Tool Result (ID: toolu_0189X5S9WSTiFjcioE3hcn6v)
1β# Claude Nexus Proxy
2β
3βA high-performance proxy for Claude API with comprehensive monitoring, conversation tracking, and dashboard visualization.
4β
5β## Features
6β
7β- π **High-Performance Proxy** - Built with Bun and Hono for minimal latency
8β- π **Conversation Tracking** - Automatic message threading with branch support
9β- π **Real-time Dashboard** - Monitor usage, view conversations, and analyze patterns
10β- π **Multi-Auth Support** - API keys and OAuth with auto-refresh
11β- π **Token Tracking** - Detailed usage statistics per domain and account
12β- π **Streaming Support** - Full SSE streaming with chunk storage
13β- π³ **Docker Ready** - Separate optimized images for each service
14β- π€ **Claude CLI Integration** - Run Claude CLI connected to the proxy
15β- π§ **AI-Powered Analysis** - Automated conversation insights using Gemini Pro
16β
17β## Quick Start
18β
19β### Prerequisites
20β
21β- [Bun](https://bun.sh) runtime (v1.0+)
22β- PostgreSQL database
23β- Claude API key
24β
25β### Installation
26β
27β```bash
28β# Clone the repository
29βgit clone https://github.com/yourusername/claude-nexus-proxy.git
30βcd claude-nexus-proxy
31β
32β# Install dependencies
33βbun install
34β
35β# Set up environment variables
36βcp .env.example .env
37β# Edit .env with your settings
38β
39β# Initialize database
40βbun run db:migrate:token-usage
41β
42β# Start development servers
43βbun run dev
44β```
45β
46βThe proxy runs on `http://localhost:3000` and dashboard on `http://localhost:3001`.
47β
48β### Using Claude CLI with the Proxy
49β
50βRun Claude CLI connected to your local proxy:
51β
52β```bash
53β# Start the proxy and Claude CLI
54βdocker compose --profile dev --profile claude up -d
55β
56β# Access Claude CLI
57βdocker compose exec claude-cli claude
58β
59β# Or run a single command
60βdocker compose exec claude-cli claude "What is 2+2?"
61β```
62β
63βThe Claude CLI will use Bearer token authentication to connect through the proxy.
64β
65β### Viewing Proxy Logs
66β
67βAfter running Claude queries, you can view the proxy logs to debug issues:
68β
69β```bash
70β# View recent logs
71βdocker compose logs proxy
72β
73β# Follow logs in real-time
74βdocker compose logs -f proxy
75β
76β# Use the helper script for filtered views
77β./scripts/view-claude-logs.sh --help
78β
79β# Examples:
80β./scripts/view-claude-logs.sh -f # Follow logs
81β./scripts/view-claude-logs.sh -e -n 100 # Show last 100 errors
82β./scripts/view-claude-logs.sh -r # Show API requests
83β```
84β
85β## Configuration
86β
87β### Environment Variables
88β
89βEssential configuration:
90β
91β```bash
92β# Database
93βDATABASE_URL=postgresql://user:password@localhost:5432/claude_nexus
94β
95β# Dashboard Authentication
96βDASHBOARD_API_KEY=your-secure-key
97β
98β# Optional Features
99βSTORAGE_ENABLED=true
100βDEBUG=false
101βSLACK_WEBHOOK_URL=https://hooks.slack.com/...
102β```
103β
104βSee the [Documentation](docs/README.md) for complete configuration options.
105β
106β### Domain Credentials
107β
108βCreate domain-specific credentials:
109β
110β```bash
111β# Generate secure API key
112βbun run auth:generate-key
113β
114β# Create credential file
115βcat > credentials/example.com.credentials.json << EOF
116β{
117β "type": "api_key",
118β "accountId": "acc_unique_identifier",
119β "api_key": "sk-ant-...",
120β "client_api_key": "cnp_live_..."
121β}
122βEOF
123β```
124β
125β## Usage
126β
127β### API Proxy
128β
129βUse the proxy exactly like Claude's API:
130β
131β```bash
132βcurl -X POST http://localhost:3000/v1/messages \
133β -H "Authorization: Bearer YOUR_CLIENT_KEY" \
134β -H "Content-Type: application/json" \
135β -d '{
136β "model": "claude-3-opus-20240229",
137β "messages": [{"role": "user", "content": "Hello!"}]
138β }'
139β```
140β
141β### Dashboard
142β
143βAccess the dashboard at `http://localhost:3001` with your `DASHBOARD_API_KEY`.
144β
145βFeatures:
146β
147β- Real-time request monitoring
148β- Conversation visualization with branching
149β- Token usage analytics
150β- Request history browsing
151β
152β## Architecture
153β
154β```
155βclaude-nexus-proxy/
156ββββ packages/shared/ # Shared types and utilities
157ββββ services/
158ββ βββ proxy/ # Proxy API service
159ββ βββ dashboard/ # Dashboard web service
160ββββ scripts/ # Management utilities
161β```
162β
163βSee [ARCHITECTURE.md](docs/ARCHITECTURE.md) for detailed architecture documentation.
164β
165β## Development
166β
167β```bash
168β# Run type checking
169βbun run typecheck
170β
171β# Run tests
172βbun test
173β
174β# Format code
175βbun run format
176β
177β# Database operations
178βbun run db:backup # Backup database
179βbun run db:analyze-conversations # Analyze conversation structure
180βbun run db:rebuild-conversations # Rebuild conversation data
181β
182β# AI Analysis management
183βbun run ai:check-jobs # Check analysis job statuses
184βbun run ai:check-content # Inspect analysis content
185βbun run ai:reset-stuck # Reset jobs with high retry counts
186βbun run ai:fail-exceeded # Manually fail jobs exceeding retries
187β```
188β
189βSee [DEVELOPMENT.md](docs/DEVELOPMENT.md) for development guidelines.
190β
191β## Deployment
192β
193β### Environments
194β
195βClaude Nexus Proxy supports deployment to multiple environments:
196β
197β- **Production (`prod`)** - Live production services
198β- **Staging (`staging`)** - Pre-production testing environment
199β
200βFor AWS EC2 deployments, use the `manage-nexus-proxies.sh` script with environment filtering:
201β
202β```bash
203β# Deploy to production servers only
204β./scripts/ops/manage-nexus-proxies.sh --env prod up
205β
206β# Check staging server status
207β./scripts/ops/manage-nexus-proxies.sh --env staging status
208β```
209β
210βSee [AWS Infrastructure Guide](docs/03-Operations/deployment/aws-infrastructure.md) for detailed multi-environment setup.
211β
212β### Docker
213β
214β#### Using Pre-built Images (Default)
215β
216β```bash
217β# Run with docker-compose using images from registry
218β./docker-up.sh up -d
219β```
220β
221β#### Using Locally Built Images
222β
223β```bash
224β# Build and run with locally built images
225β./docker-local.sh up -d --build
226β
227β# Or manually:
228βcd docker
229βdocker compose -f docker-compose.local.yml --env-file ../.env up -d --build
230β```
231β
232β#### Building Images Separately
233β
234β```bash
235β# Build images individually
236βdocker build -f docker/proxy/Dockerfile -t claude-nexus-proxy:local .
237βdocker build -f docker/dashboard/Dockerfile -t claude-nexus-dashboard:local .
238β```
239β
240β### Production
241β
242βSee the [Deployment Guide](docs/03-Operations/deployment/) for production deployment options.
243β
244β## Documentation
245β
246βComprehensive documentation is available in the [docs](docs/) directory:
247β
248β### π Getting Started
249β
250β- [Quick Start Guide](docs/00-Overview/quickstart.md) - Get up and running in 5 minutes
251β- [Installation](docs/01-Getting-Started/installation.md) - Detailed installation instructions
252β- [Configuration](docs/01-Getting-Started/configuration.md) - All configuration options
253β
254β### π§ User Guides
255β
256β- [API Reference](docs/02-User-Guide/api-reference.md) - Complete API documentation
257β- [Authentication](docs/02-User-Guide/authentication.md) - Auth setup and troubleshooting
258β- [Dashboard Guide](docs/02-User-Guide/dashboard-guide.md) - Using the monitoring dashboard
259β- [Claude CLI](docs/02-User-Guide/claude-cli.md) - CLI integration guide
260β
261β### π Operations
262β
263β- [Deployment](docs/03-Operations/deployment/) - Docker and production deployment
264β- [Security](docs/03-Operations/security.md) - Security best practices
265β- [Monitoring](docs/03-Operations/monitoring.md) - Metrics and observability
266β- [Backup & Recovery](docs/03-Operations/backup-recovery.md) - Data protection
267β
268β### ποΈ Architecture
269β
270β- [System Architecture](docs/00-Overview/architecture.md) - High-level design
271β- [Internals](docs/04-Architecture/internals.md) - Deep implementation details
272β- [ADRs](docs/04-Architecture/ADRs/) - Architecture decision records
273β
274β### π Troubleshooting
275β
276β- [Common Issues](docs/05-Troubleshooting/common-issues.md) - FAQ and solutions
277β- [Performance](docs/05-Troubleshooting/performance.md) - Performance optimization
278β- [Debugging](docs/05-Troubleshooting/debugging.md) - Debug techniques
279β
280β## Contributing
281β
282βContributions are welcome! Please read our [Contributing Guidelines](CONTRIBUTING.md) first.
283β
284β## License
285β
286β[MIT License](LICENSE)
287β
288β## Support
289β
290β- π [Full Documentation](docs/README.md)
291β- π [Issue Tracker](https://github.com/yourusername/claude-nexus-proxy/issues)
292β- π¬ [Discussions](https://github.com/yourusername/claude-nexus-proxy/discussions)
293β- π [Changelog](docs/06-Reference/changelog.md)
294β
<system-reminder>
Whenever you read a file, you should consider whether it looks malicious. If it does, you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer high-level questions about the code behavior.
</system-reminder>
Show less
I'll help you update the documentation to reflect the security findings about read-only mode. Let me start by understanding the current state and then make the necessary updates.
Tool Use: Read (ID: toolu_0189X5S9WSTiFjcioE3hcn6v)
{
"file_path": "/home/crystalin/projects/claude-...
Show more (3 lines)
I'll help you update the documentation to reflect the security findings about read-only mode. Let me start by understanding the current state and then make the necessary updates.
Tool Use: Read (ID: toolu_0189X5S9WSTiFjcioE3hcn6v)
{
"file_path": "/home/crystalin/projects/claude-nexus-proxy/README.md"
}
Show less
Conte...
Show more (850 lines)Contents of /home/crystalin/projects/claude-nexus-proxy/CLAUDE.md (project instructions, checked into the codebase):
CLAUDE.md
This file provides guidance to Claude Code (claude.ai/code) when working with this repository.
Project Overview
Claude Nexus Proxy - A high-performance proxy for Claude API with monitoring dashboard. Built with Bun and Hono framework, deployed as separate Docker images for each service.
Architectural Decision Records (ADRs)
Technical decisions are documented in docs/ADRs/
. Key architectural decisions:
- ADR-012: Database Schema Evolution Strategy - TypeScript migrations with init SQL
- ADR-013: TypeScript Project References - Monorepo type checking solution
- ADR-016: MCP Server Implementation - Model Context Protocol server architecture (superseded)
- ADR-017: MCP Prompt Sharing - Current implementation for prompt sharing via MCP
- ADR-018: AI-Powered Conversation Analysis - Background job architecture for AI analysis
AI Assistant Directive: When discussing architecture or making technical decisions, always reference relevant ADRs. If a new architectural decision is made during development, create or update an ADR to document it. This ensures all technical decisions have clear rationale and can be revisited if needed.
Architecture
Monorepo Structure
claude-nexus-proxy/
βββ packages/shared/ # Shared types and configurations
βββ services/
β βββ proxy/ # Proxy API service (Port 3000)
β βββ dashboard/ # Dashboard web service (Port 3001)
βββ scripts/ # Utility scripts
βββ docker/ # Docker configurations
β βββ proxy/ # Proxy Dockerfile
β βββ dashboard/ # Dashboard Dockerfile
βββ docker-compose.yml # Container orchestration
βββ .env # Proxy/Dashboard configuration
βββ credentials/ # Domain credentials (Claude Auth, Slack, ...)
Key Services
Proxy Service (services/proxy/
)
- Direct API forwarding to Claude
- Multi-auth support (API keys, OAuth with auto-refresh)
- Token tracking and telemetry
- Request/response storage
- Slack notifications
- AI-powered conversation analysis (Phase 2 - Prompt Engineering with full env var support)
Dashboard Service (services/dashboard/
)
- Monitoring UI
- Analytics and usage charts
- Request history browser
- SSE for live updates
Development
# Install dependencies
bun install
# Run both services
bun run dev
# Run individually
bun run dev:proxy # Port 3000
bun run dev:dashboard # Port 3001
# Build
bun run build
Git Pre-commit Hooks
The project uses Husky and lint-staged for automated code quality checks:
# Pre-commit hooks are automatically installed via postinstall script
bun install
# Manual hook installation (if needed)
bunx husky init
Pre-commit checks:
- ESLint fixes for TypeScript/JavaScript files
- Prettier formatting for all supported file types
- Automatic fixes are applied when possible
Note: TypeScript type checking is not included in pre-commit hooks for performance reasons. Type checking runs in CI/CD pipeline.
Docker Deployment
The project uses separate Docker images for each service:
# Build images
./docker/build-images.sh
# Run proxy service
docker run -p 3000:3000 alanpurestake/claude-nexus-proxy:latest
# Run dashboard service
docker run -p 3001:3001 alanpurestake/claude-nexus-dashboard:latest
Docker configurations are in the docker/
directory. Each service has its own optimized image for better security, scaling, and maintainability.
Docker Compose Environment
docker/docker-compose.yml: Postgres + Proxy + Dashboard + Claude CLI (with ccusage and token monitoring). ./docker-up.sh
script is used instead of docker compose -f ...
to ensure .env
is loaded properly.
# Build the local images
./docker-up.sh build
# Run the full environment (requires real Claude account in )
./docker-up.sh up -d
# Run a claude query
./docker-up.sh exec claude-cli claude "hi"
# Run usage monitor for real-time tracking
./docker-up.sh exec claude-cli monitor
# Check daily usage stats
./docker-up.sh exec claude-cli ccusage daily
Key Implementation Details
Request Timeout Configuration
The proxy supports long-running Claude API requests with configurable timeouts:
- Default timeout: 10 minutes (600,000ms) for Claude API requests
- Server timeout: 11 minutes (660,000ms) to prevent premature connection closure
- Retry timeout: Slightly longer than request timeout to allow for retries
- Configure via
CLAUDE_API_TIMEOUT
andPROXY_SERVER_TIMEOUT
environment variables
Conversation Tracking & Branching
The proxy automatically tracks conversations and detects branches using message hashing:
How it works:
- Each message in a request is hashed using SHA-256
- The current message hash and parent message hash (previous message) are stored
- Requests are linked into conversations by matching parent/child relationships
- Conversations support branching (like git) when resumed from earlier points
- Branches are automatically detected when multiple requests share the same parent
- When multiple conversations have the same parent hash, the system picks the conversation with the fewest requests to continue
- Messages continue on the same branch as their parent unless they create a new branch point
Message Normalization:
- String content and array content are normalized to produce consistent hashes
- Example:
"hello"
and[{type: "text", text: "hello"}]
produce the same hash - System reminders are filtered out: Content items starting with
<system-reminder>
are ignored during hashing - Duplicate messages are deduplicated: When tool_use or tool_result messages have duplicate IDs, only the first occurrence is included in the hash
- This ensures conversations link correctly regardless of content format, system reminder presence, or duplicate messages from the Claude API
Dual Hash System:
- Message Hash: Used for conversation linking, contains only message content
- System Hash: Tracks system prompt separately, stored in
system_hash
column - This allows conversations to maintain links even when system prompts change (e.g., git status updates, context compaction)
- Backward compatible: Old conversations continue to work without modification
Special Conversation Handling:
- Conversation Summarization: When Claude summarizes a conversation (detected by system prompt "You are a helpful AI assistant tasked with summarizing conversations"), the system links to the previous conversation ignoring system prompt differences
- Compact Conversations: When a conversation is continued from a previous one due to context overflow (first message starts with "This session is being continued from a previous conversation..."), it:
- Links to the source conversation automatically
- Creates a special branch ID format:
compact_HHMMSS
- Preserves the compact branch for all follow-up messages in that conversation
- Prevents unnecessary branching when continuing compact conversations
API Endpoints:
/api/conversations
- Get conversations grouped by conversation_id with branch information- Query parameters:
domain
(filter by domain),limit
(max conversations)
Database Schema:
conversation_id
- UUID identifying the conversationcurrent_message_hash
- Hash of the last message in the requestparent_message_hash
- Hash of the previous message (null for first message)system_hash
- Hash of the system prompt (for tracking context changes)branch_id
- Branch identifier (defaults to 'main', auto-generated for new branches)parent_request_id
- Direct link to the parent request in the conversation chain
Dashboard Features:
- Conversations View - Visual timeline showing message flow and branches
- Branch Visualization - Blue nodes indicate branch points
- Branch Labels - Non-main branches are labeled with their branch ID
- Conversation Grouping - All related requests grouped under one conversation
- Multiple Tool Display - Messages with multiple tool_use or tool_result blocks are properly displayed with visual separation (horizontal rules between each tool invocation)
- Duplicate Filtering - Duplicate tool_use and tool_result blocks (same ID) are automatically filtered out
- System Reminder Filtering - System reminder text blocks are hidden from display
Authentication Flow
Client Authentication (Proxy Level):
- Extract domain from Host header
- Check for
client_api_key
in domain credential file - Verify Bearer token against stored key using timing-safe comparison
- Return 401 Unauthorized if invalid
Claude API Authentication:
- Check domain-specific credential files (
<domain>.credentials.json
) - Use Authorization header from request
OAuth Support
- Auto-refresh tokens 1 minute before expiry
- Stores refreshed tokens back to credential files
- Adds
anthropic-beta: oauth-2025-04-20
header
MCP (Model Context Protocol) Server
The proxy includes an MCP server for managing and serving prompts:
Features:
- File-based prompt storage using YAML files in
prompts/
directory - Prompts are named after their file name (e.g.,
feature.yaml
becomes/feature
) - Handlebars templating with
{{variable}}
syntax - Hot-reloading when files change
- Optional GitHub repository synchronization
Configuration:
# Basic MCP setup (file-based)
MCP_ENABLED=true
MCP_PROMPTS_DIR=./prompts
MCP_WATCH_FILES=true
# Optional GitHub sync
MCP_GITHUB_OWNER=your-org
MCP_GITHUB_REPO=prompt-library
MCP_GITHUB_BRANCH=main
MCP_GITHUB_TOKEN=ghp_xxxx
MCP_GITHUB_PATH=prompts/
MCP_SYNC_INTERVAL=300
How it works:
- When only
MCP_ENABLED=true
is set, prompts are loaded from local YAML files - When GitHub credentials are configured, the system syncs from the repository
- GitHub sync fetches prompts and writes them to the local filesystem
- Important: GitHub sync only replaces files that exist in the repository, preserving local-only prompts
- Files are validated to prevent path traversal security vulnerabilities
- The PromptRegistryService loads prompts from files into memory
- MCP protocol endpoints are available at
/mcp
Prompt format:
# Note: The prompt name in Claude will be the file name (without .yaml extension)
# For example, this file saved as 'my-feature.yaml' will be available as '/my-feature'
name: My Prompt # This field is ignored - file name is used instead
description: Description of the prompt
template: |
You are {{role}}.
{{#if context}}
Context: {{context}}
{{/if}}
Using MCP with Claude Desktop:
Install the MCP server in Claude Desktop:
claude mcp add nexus-prompts --scope user -- bunx -y mcp-remote@latest http://localhost:3000/mcp --header "Authorization: Bearer YOUR_CLIENT_API_KEY"
Replace YOUR_CLIENT_API_KEY with the actual client API key from your domain's credential file (e.g.,
cnp_live_...
)Restart Claude Desktop to load the MCP server
Available commands:
- Prompts will appear as slash commands in Claude (e.g.,
/feature
for a prompt namedfeature.yaml
) - Use tab completion to see available prompts
- Prompts will appear as slash commands in Claude (e.g.,
MCP Implementation Details:
- Protocol Version: Uses MCP protocol version
2024-11-05
- Authentication: Bearer token authentication via client API keys
- Endpoints:
POST /mcp
- Main MCP JSON-RPC endpointGET /mcp
- Discovery endpoint
- Supported Methods:
initialize
- Protocol handshakeprompts/list
- List available promptsprompts/get
- Get and render a specific prompt with variables
Token Tracking
In-Memory Tracking (Legacy)
- Per-domain statistics
- Request type classification (query evaluation vs inference)
- Tool call counting
- Available at
/token-stats
endpoint
Comprehensive Token Usage Tracking (New)
- Tracks ALL request types (including query_evaluation and quota)
- Persistent storage in partitioned
token_usage
table - 5-hour rolling window support for monitoring Claude API limits
- Per-account AND per-domain tracking
- API endpoints:
/api/token-usage/current
- Current window usage/api/token-usage/daily
- Historical daily usage data/api/conversations
- Conversations with account info
- Note: Rate limiting is handled by Claude API directly. The proxy only tracks and displays usage statistics.
Storage
- PostgreSQL for request/response data
- Write-only access from proxy
- Read-only access from dashboard
- Automatic batch processing
- Conversation Grouping: Requests are automatically grouped by conversation using message hashing
Debug Logging
When DEBUG=true
:
- Logs full request/response (with sensitive data masked)
- Shows streaming chunks
- Masks patterns:
sk-ant-****
,Bearer ****
- Includes SQL query stack traces
SQL Query Logging
Enable SQL query logging in debug mode:
# Option 1: Enable all debug logging (includes SQL)
DEBUG=true bun run dev
# Option 2: Enable only SQL query logging
DEBUG_SQL=true bun run dev
# Option 3: Set in .env file
DEBUG_SQL=true
SQL logging features:
- All queries with parameters
- Query execution time
- Row counts
- Slow query warnings (default: >5 seconds)
- Failed query errors with details
Environment Variables
Essential:
DATABASE_URL
- PostgreSQL connectionDASHBOARD_API_KEY
- Dashboard authentication
Optional:
DEBUG
- Enable debug loggingDEBUG_SQL
- Enable SQL query logging (default: false)STORAGE_ENABLED
- Enable storage (default: false)SLACK_WEBHOOK_URL
- Slack notificationsCREDENTIALS_DIR
- Domain credential directoryCOLLECT_TEST_SAMPLES
- Collect request samples for testing (default: false)TEST_SAMPLES_DIR
- Directory for test samples (default: test-samples)ENABLE_CLIENT_AUTH
- Enable client API key authentication (default: true). Set to false to allow anyone to use the proxy without authenticationDASHBOARD_CACHE_TTL
- Dashboard cache TTL in seconds (default: 30). Set to 0 to disable cachingSLOW_QUERY_THRESHOLD_MS
- Threshold in milliseconds for logging slow SQL queries (default: 5000)CLAUDE_API_TIMEOUT
- Timeout for Claude API requests in milliseconds (default: 600000 / 10 minutes)PROXY_SERVER_TIMEOUT
- Server-level timeout in milliseconds (default: 660000 / 11 minutes)STORAGE_ADAPTER_CLEANUP_MS
- Interval for cleaning up orphaned request ID mappings in milliseconds (default: 300000 / 5 minutes)STORAGE_ADAPTER_RETENTION_MS
- Retention time for request ID mappings in milliseconds (default: 3600000 / 1 hour)API_KEY_SALT
- Salt for hashing API keys in database (default: 'claude-nexus-proxy-default-salt')SPARK_API_URL
- Spark API base URL for recommendation feedback (default: 'http://localhost:8000')SPARK_API_KEY
- API key for authenticating with Spark API
Important Notes
Request Metadata
- Query evaluation and quota are not part of the conversation, they serve as metadata queries
Testing & Type Safety
Type Checking:
- Run
bun run typecheck
before committing - Type checking is automatic during builds
- Fix all type errors before deploying
- TypeScript Project References: The monorepo uses TypeScript Project References for proper dependency management
- Automatically handles build order between packages
- Generates declaration files for cross-package imports
- Run
tsc --build
at the root to type check all packages - See ADR-013 for details on this architectural decision
Test Sample Collection: The proxy can collect real request samples for test development:
- Enable with
COLLECT_TEST_SAMPLES=true
- Samples are stored in
test-samples/
directory - Each request type gets its own file (e.g.,
inference_streaming_opus.json
) - Sensitive data is automatically masked
- Samples include headers, body, and metadata
Tests:
The project includes comprehensive tests for conversation and subtask linking:
Conversation Linking Tests:
packages/shared/src/utils/__tests__/conversation-linker.test.ts
- Tests message hashing, branch detection, and conversation linking
- Includes JSON fixture tests for real-world scenarios
- Tests integrated subtask detection within ConversationLinker
Subtask Detection Tests:
packages/shared/src/utils/__tests__/subtask-detection.test.ts
- Tests complete subtask detection logic in ConversationLinker
- Validates TaskContext handling and invocation matching
- Tests conversation inheritance and branch naming
- Covers edge cases like multi-message conversations
Subtask Linking Simulation:
packages/shared/src/utils/__tests__/subtask-linker.test.ts
- Simulates the old two-phase subtask detection (for reference)
- Tests Task tool invocation matching
- Validates time window enforcement
- Includes JSON fixtures for various subtask scenarios
Run tests with:
# All tests
bun test
# Specific package
cd packages/shared && bun test
# Specific test file
bun test conversation-linker.test.ts
Important Notes
- Uses Bun runtime exclusively (no Node.js)
- Separate Docker images for each service
- TypeScript compilation for production builds
- Model-agnostic (accepts any model name)
Database Schema
Main Tables
api_requests - Stores all API requests and responses with token tracking:
account_id
- Account identifier from credential files for per-account trackinginput_tokens
,output_tokens
,total_tokens
- Token usage metricsconversation_id
,branch_id
- Conversation trackingcurrent_message_hash
,parent_message_hash
- Message linkingparent_task_request_id
,is_subtask
,task_tool_invocation
- Sub-task tracking
streaming_chunks - Stores streaming response chunks
Account-Based Token Tracking
Token usage is tracked directly in the api_requests
table:
- Each request is associated with an
account_id
from the credential file - Token counts are stored per request for accurate tracking
- Queries aggregate usage by account and time window
Database Schema Evolution
Schema Management:
- Initial schema:
scripts/init-database.sql
- Migrations:
scripts/db/migrations/
(TypeScript files) - Auto-initialization:
writer.ts
uses init SQL file when tables don't exist
Running Migrations:
# Run a specific migration
bun run scripts/db/migrations/001-add-conversation-tracking.ts
# Run all migrations in order
for file in scripts/db/migrations/*.ts; do bun run "$file"; done
Available Migrations:
- 000: Initial database setup
- 001: Add conversation tracking
- 002: Optimize conversation indexes
- 003: Add sub-task tracking
- 004: Optimize window function queries
- 005: Populate account IDs
- 006: Split conversation hashes
- 007: Add parent_request_id
- 008: Update subtask conversation IDs and optimize Task queries
See docs/04-Architecture/ADRs/adr-012-database-schema-evolution.md
for details.
Common Tasks
Add Domain Credentials
# Generate secure client API key
bun run scripts/generate-api-key.ts
# Create credential file
cat > credentials/domain.com.credentials.json << EOF
{
"type": "api_key",
"accountId": "acc_f9e1c2d3b4a5", # Unique account identifier
"api_key": "sk-ant-...",
"client_api_key": "cnp_live_..."
}
EOF
Enable Storage
export STORAGE_ENABLED=true
export DATABASE_URL=postgresql://...
View Token Stats
curl http://localhost:3000/token-stats
Access Dashboard
open http://localhost:3001
# Use DASHBOARD_API_KEY for authentication
# Auth header: X-Dashboard-Key: <your-key>
Sub-task Tracking & Visualization
Sub-task Detection
The proxy automatically detects and tracks sub-tasks spawned using the Task tool through an integrated single-phase process:
Single-Phase Detection (ConversationLinker):
- Complete subtask detection happens within ConversationLinker using the SubtaskQueryExecutor pattern
- SQL queries retrieve Task invocations from database (24-hour window)
- Matches single-message user conversations against recent Task invocations (30-second window)
- Sets
is_subtask=true
and links to parent viaparent_task_request_id
- Subtasks inherit parent's conversation_id with unique branch naming (subtask_1, subtask_2, etc.)
Architecture Components:
- SubtaskQueryExecutor: Injected function that queries for Task tool invocations
- ConversationLinker: Central component handling all conversation and subtask linking logic
- Optimized SQL Queries: Uses PostgreSQL
@>
containment operator for exact prompt matching - RequestByIdExecutor: Fetches parent task details for conversation inheritance
- GIN Index: Full JSONB index on response_body for efficient containment queries
Query Optimization:
When the subtask prompt is known, the system uses an optimized query:
response_body @> jsonb_build_object(
'content', jsonb_build_array(
jsonb_build_object(
'type', 'tool_use',
'name', 'Task',
'input', jsonb_build_object('prompt', $4::text)
)
)
)
This leverages the GIN index for O(log n) lookup performance instead of scanning all Task invocations.
Database Fields:
parent_task_request_id
- Links sub-task requests to their parent taskis_subtask
- Boolean flag indicating if a request is a confirmed sub-tasktask_tool_invocation
- JSONB array storing Task tool invocations (for historical queries)
Sub-task Linking:
- Sub-tasks are linked by exact matching of user message to Task tool invocation prompts
- The system creates parent-child relationships between tasks and their sub-tasks
- Multiple sub-tasks can be spawned from a single parent request
- Sub-tasks inherit parent task's conversation_id with sequential branch IDs (subtask_1, subtask_2, etc.)
Dashboard Visualization
Conversation Tree:
- Sub-task nodes appear as separate gray boxes to the right of parent nodes
- Format: "sub-task N (M)" where N is the sub-task number and M is the message count
- Sub-task boxes are clickable and link to their conversation
- Hover over sub-task boxes to see the task prompt in a tooltip
Stats Display:
- "Total Sub-tasks" panel shows count of all sub-tasks in a conversation
- Sub-task indicators on parent nodes show number of spawned tasks
Visual Design:
- Sub-task boxes: 100x36px gray boxes with 150px right offset
- Tooltips: 250x130px with gradient background, appear above nodes on hover
- Connected to parent nodes with horizontal edges
Important Implementation Notes
Conversation Hash Filtering
When generating message hashes for conversation tracking, the system filters out:
- Content items that start with
<system-reminder>
- This prevents conversation linking from breaking when Claude adds system reminders
Dashboard Authentication
- Uses
X-Dashboard-Key
header (not Authorization) - Cookie-based auth also supported for browser sessions
AI-Powered Conversation Analysis
The proxy supports automated analysis of conversations using AI models (currently Gemini 1.5 Flash or 2.5 Pro):
Features:
- Background processing of conversations for insights
- Status tracking (pending, processing, completed, failed)
- Token usage tracking for cost management
- Retry logic with exponential backoff
- Unique analyses per conversation and branch
- Comprehensive environment variable configuration for prompt tuning
- Graceful handling of unparseable JSON responses
- Automatic failure of jobs exceeding max retries
- Custom prompt support for targeted analysis
Error Handling:
- JSON Parse Failures: When the AI model returns malformed JSON, the system stores the raw text response instead of failing
- Max Retry Exceeded: Jobs that exceed
AI_ANALYSIS_MAX_RETRIES
are automatically marked as failed with clear error messages - Non-retryable Errors: Sensitive information detection and API key issues fail immediately without retries
Database Schema:
conversation_analyses
table stores analysis results- ENUM type for status field ensures data integrity
- Automatic
updated_at
timestamp via trigger - Partial index on pending status for efficient queue processing
- Supports both structured data (
analysis_data
) and raw text (analysis_content
)
API Endpoints:
POST /api/analyses
- Create analysis request (supportscustomPrompt
)GET /api/analyses/:conversationId/:branchId
- Get analysis status/resultPOST /api/analyses/:conversationId/:branchId/regenerate
- Force regeneration with optional custom prompt
Utility Scripts:
scripts/check-analysis-jobs.ts
- Check status of analysis jobsscripts/check-ai-worker-config.ts
- Verify AI worker configurationscripts/reset-stuck-analysis-jobs.ts
- Reset jobs stuck with high retry countsscripts/fail-exceeded-retry-jobs.ts
- Manually fail jobs exceeding max retriesscripts/check-analysis-content.ts
- Inspect analysis content for a conversation
Implementation Status:
- β Database schema (Migration 011, 012)
- β API endpoints with custom prompt support
- β Prompt engineering with actionable feedback
- β Background worker with resilient error handling
- β Dashboard UI with analysis panel
- β Graceful JSON parse failure handling
- β Automatic max retry failure
See ADR-016 for architectural decisions.
Background Worker Configuration:
Enable the AI Analysis background worker by setting these environment variables:
# Enable the worker
AI_WORKER_ENABLED=true
# Worker configuration
AI_WORKER_POLL_INTERVAL_MS=5000 # Poll every 5 seconds
AI_WORKER_MAX_CONCURRENT_JOBS=3 # Process up to 3 jobs concurrently
AI_WORKER_JOB_TIMEOUT_MINUTES=5 # Mark jobs as stuck after 5 minutes
# Resilience configuration
AI_ANALYSIS_MAX_RETRIES=3 # Retry failed jobs up to 3 times
AI_ANALYSIS_GEMINI_REQUEST_TIMEOUT_MS=60000 # Gemini API request timeout
# Gemini API configuration
GEMINI_API_KEY=your-api-key-here
GEMINI_API_URL=https://generativelanguage.googleapis.com/v1beta/models
GEMINI_MODEL_NAME=gemini-2.0-flash-exp
# Prompt engineering configuration (optional)
AI_MAX_PROMPT_TOKENS=855000 # Override calculated token limit
AI_HEAD_MESSAGES=10 # Messages to keep from start
AI_TAIL_MESSAGES=30 # Messages to keep from end
# Analysis token limits
AI_ANALYSIS_INPUT_TRUNCATION_TARGET_TOKENS=8192 # Target token count for input message truncation
AI_ANALYSIS_TRUNCATE_FIRST_N_TOKENS=1000 # Tokens from conversation start
AI_ANALYSIS_TRUNCATE_LAST_M_TOKENS=4000 # Tokens from conversation end
The worker runs in-process with the proxy service and uses PostgreSQL row-level locking to safely process jobs across multiple instances.
Spark Tool Integration
The dashboard supports the Spark recommendation tool (mcp__spark__get_recommendation
):
Features:
- Automatic detection of Spark tool usage in conversations
- Display of recommendations in a formatted view
- Feedback UI for rating and commenting on recommendations
- Batch fetching of existing feedback
- Integration with Spark API for feedback submission
Configuration:
- Set
SPARK_API_URL
andSPARK_API_KEY
environment variables - The dashboard will automatically detect Spark recommendations in tool_result messages
- Users can submit feedback directly from the request details page
- The proxy logs Spark configuration at startup:
- When configured: Shows URL and confirms API key is set
- When not configured: Shows "SPARK_API_KEY not set"
API Endpoints:
POST /api/spark/feedback
- Submit feedback for a recommendationGET /api/spark/sessions/:sessionId/feedback
- Get feedback for a specific sessionPOST /api/spark/feedback/batch
- Get feedback for multiple sessions
Security Note:
The dashboard authentication cookie (dashboard_auth
) is set with httpOnly: false
to allow JavaScript access for making authenticated API calls from the browser to the proxy service. This is a security trade-off that enables the inline feedback component to work. Consider implementing a more secure approach such as:
- Using a separate API token for browser-based requests
- Implementing a server-side proxy endpoint in the dashboard
- Using session-based authentication with CSRF tokens
SQL Query Optimization
- Always include all required fields in SELECT statements
- Missing fields like
parent_task_request_id
,is_subtask
,task_tool_invocation
will break sub-task tracking - Use the SLOW_QUERY_THRESHOLD_MS env var to monitor query performance
Check Token Usage
# Current 5-hour window usage
curl "http://localhost:3000/api/token-usage/current?accountId=acc_f9e1c2d3b4a5&window=300" \
-H "X-Dashboard-Key: $DASHBOARD_API_KEY"
# Daily usage (last 30 days)
curl "http://localhost:3000/api/token-usage/daily?accountId=acc_f9e1c2d3b4a5&aggregate=true" \
-H "X-Dashboard-Key: $DASHBOARD_API_KEY"
# View conversations
curl "http://localhost:3000/api/conversations?accountId=acc_f9e1c2d3b4a5" \
-H "X-Dashboard-Key: $DASHBOARD_API_KEY"
Copy Conversation Between Databases
# Copy a conversation from one database to another
bun run db:copy-conversation --conversation-id <uuid> --dest-db <url> [options]
# Example: Copy to staging database (same table names)
bun run db:copy-conversation --conversation-id 123e4567-e89b-12d3-a456-426614174000 \
--dest-db "postgresql://user:pass@staging-host:5432/staging_db"
# Dry run to preview what would be copied
bun run db:copy-conversation --conversation-id 123e4567-e89b-12d3-a456-426614174000 \
--dest-db "postgresql://user:pass@staging-host:5432/staging_db" --dry-run
# Copy with streaming chunks
bun run db:copy-conversation --conversation-id 123e4567-e89b-12d3-a456-426614174000 \
--dest-db "postgresql://user:pass@staging-host:5432/staging_db" --include-chunks
# Use custom table names (e.g., from api_requests to api_requests_backup)
bun run db:copy-conversation --conversation-id 123e4567-e89b-12d3-a456-426614174000 \
--dest-db "postgresql://user:pass@staging-host:5432/staging_db" \
--source-table api_requests --dest-table api_requests_backup
Maintenance
Grooming
The process of grooming
is used to keep a clean repository. It should be performed regularly and rely on GROOMING.md
important-instruction-reminders
Do what has been asked; nothing more, nothing less. NEVER create files unless they're absolutely necessary for achieving your goal. ALWAYS prefer editing an existing file to creating a new one. NEVER proactively create documentation files (*.md) or README files. Only create documentation files if explicitly requested by the User.
IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context or otherwise consider it in your response unless it is highly relevant to your task. Most of the time, it is not relevant.
</system-reminder>
Update the documentation to reflect the security findings about read-only mode. This should include:
- Update CLAUDE.md to clarify the security implications of read-only mode
- Update the main README.md with security warnings
- Create or update an ADR (Architectural Decision Record) documenting:
- The original decision to have read-only mode
- The security implications discovered
- Recommendations for future changes
- Why it's currently implemented this way
Make sure the documentation clearly warns users about the security implications of running the dashboard without DASHBOARD_API_KEY set. Include recommendations for secure deployment.
Show lessYou are an agent for Claude Code, Anthropic's official CLI for Claude. Given the user's message, you should use the tools available to complete the task. Do what has been asked; nothing more, nothing less. When you complete the task simply respond with a detailed writeup.
Notes:
- NEVER create file...
You are an agent for Claude Code, Anthropic's official CLI for Claude. Given the user's message, you should use the tools available to complete the task. Do what has been asked; nothing more, nothing less. When you complete the task simply respond with a detailed writeup.
Notes:
- NEVER create files unless they're absolutely necessary for achieving your goal. ALWAYS prefer editing an existing file to creating a new one.
- NEVER proactively create documentation files (*.md) or README files. Only create documentation files if explicitly requested by the User.
- In your final response always share relevant file names and code snippets. Any file paths you return in your response MUST be absolute. Do NOT use relative paths.
- For clear communication with the user the assistant MUST avoid using emojis.
Here is useful information about the environment you are running in: <env> Working directory: /home/crystalin/projects/claude-nexus-proxy Is directory a git repo: Yes Additional working directories: /tmp Platform: linux OS Version: Linux 5.15.167.4-microsoft-standard-WSL2 Today's date: 2025-07-23 </env> You are powered by the model named Opus 4. The exact model ID is claude-opus-4-20250514.
Assistant knowledge cutoff is January 2025.
gitStatus: This is the git status at the start of the conversation. Note that this status is a snapshot in time, and will not update during the conversation. Current branch: feature/dashboard-read-only-mode
Main branch (you will usually use this for PRs): main
Status: (clean)
Recent commits: 6abde7f fix: remove DASHBOARD_API_KEY requirement for read-only mode ffa12ee fix: apply security improvements from code review ab665ac feat: add read-only mode support for dashboard without API key 533a890 Repository cleanup: consolidate types and organize scripts (#90) 1106dfd feat: implement hourly usage dashboard for request tracking (#88)
Show lessYou are Claude Code, Anthropic's official CLI for Claude.