mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-07 03:00:29 +00:00
Invert the docs convention so the Mintlify-published site lives under docs/public/ and internal artifacts (strategy docs, brainstorms, plans, etc.) sit at docs/ root or docs/internal/. Tools that default to writing into docs/ now land in the catch-all instead of leaking into the published tree. - Move Mintlify content (administration/, agents/, api-reference/, changelog/, core-concepts/, examples/, execution/, getting-started/, human-tools/, integrations/, languages/, reference/, tutorials/, workflows/, images/, logo/, docs.json, favicon.svg, dot-highlight.js) into docs/public/. - Collapse docs-internal/ into docs/internal/. - Update Rust path references (fabro-api/build.rs, fabro-server, fabro-dev), TypeScript generator arg, CI path filters, clippy.toml reasons, AGENTS.md/CLAUDE.md, and README.md image refs. Mintlify dashboard project root must be updated to docs/public/ in a follow-up. .mintignore move/trim and .claude/skills/ updates land in a separate commit.
67 lines
3.3 KiB
Text
67 lines
3.3 KiB
Text
---
|
|
title: "VPN Connections"
|
|
description: "Connect sandbox environments to private networks via VPN"
|
|
---
|
|
|
|
<Warning>
|
|
VPN connections are **coming soon** and not yet available. This page describes the planned feature.
|
|
</Warning>
|
|
|
|
VPN connections enable sandboxes to connect to private networks, giving agents access to internal services, databases, and APIs that aren't reachable over the public internet.
|
|
|
|
## Use cases
|
|
|
|
- **Access private services** — connect to internal APIs, databases, or staging environments behind a corporate firewall
|
|
- **Test against production-like infrastructure** — reach services on a private network without exposing them publicly
|
|
- **Team collaboration** — share a VPN network so sandboxes and developer machines can communicate directly
|
|
|
|
## Supported providers
|
|
|
|
| Provider | Authentication | Best for |
|
|
|---|---|---|
|
|
| **Tailscale** | Browser login or auth key | Mesh networking, zero-config connectivity |
|
|
| **OpenVPN** | Client configuration file | Corporate VPNs, existing OpenVPN infrastructure |
|
|
|
|
## How it works
|
|
|
|
When VPN is enabled, Fabro installs the VPN client inside the sandbox, connects to the specified network, and verifies connectivity before the workflow begins. Once connected, the sandbox receives a VPN IP address and can reach all resources on the private network.
|
|
|
|
### Tailscale
|
|
|
|
Tailscale provides two authentication methods:
|
|
|
|
- **Auth key** — non-interactive authentication suitable for automated runs and CI/CD pipelines. You provide a Tailscale auth key and the sandbox connects without manual intervention.
|
|
- **Browser login** — interactive authentication where Fabro generates a login URL. You visit the URL in your browser to authorize the sandbox device on your Tailscale network.
|
|
|
|
### OpenVPN
|
|
|
|
OpenVPN uses a client configuration file (`.ovpn`) containing connection parameters, certificates, and encryption settings. The sandbox installs the OpenVPN client, uploads the configuration, and connects in the background.
|
|
|
|
## Example workflow
|
|
|
|
With a VPN connection configured, agents can reach internal services like a private database. This workflow investigates a performance issue by querying the staging database directly:
|
|
|
|
<Frame>
|
|
<img src="/images/vpn-connections-workflow.svg" alt="VPN workflow: Start → Analyze Slow Queries → Fix Query → Review Changes → Exit, with a Revise loop back to Fix Query" />
|
|
</Frame>
|
|
|
|
```dot
|
|
digraph InvestigateSlowQuery {
|
|
graph [goal="Identify and fix the slow query causing timeouts on the orders page"]
|
|
|
|
start [shape=Mdiamond, label="Start"]
|
|
exit [shape=Msquare, label="Exit"]
|
|
|
|
analyze [label="Analyze Slow Queries", prompt="Connect to the staging database at staging-db.internal:5432 and run EXPLAIN ANALYZE on the queries used by the orders page. Identify the slowest query."]
|
|
fix [label="Fix Query", prompt="Add or modify indexes and rewrite the slow query to resolve the performance issue. Verify the fix with EXPLAIN ANALYZE."]
|
|
review [shape=hexagon, label="Review Changes"]
|
|
|
|
start -> analyze -> fix -> review
|
|
review -> exit [label="[A] Approve"]
|
|
review -> fix [label="[R] Revise"]
|
|
}
|
|
```
|
|
|
|
## Verification
|
|
|
|
After connecting, Fabro verifies the VPN connection by checking that the sandbox has a VPN interface and can reach the private network. If the connection fails, the run reports the error before workflow execution begins.
|