Secure, per-user access to every workspace.
One long-lived proxy sits behind a single *.ws.fastverk.com wildcard and does the load-bearing work: resolve a subdomain to a workspace pod, check the session and ownership, and proxy HTTP, the web IDE's WebSockets, and SSH-over-WebSocket — without minting a single per-workspace DNS record, cert, or Ingress.
One proxy, not an Ingress per workspace.
Give every developer private access to their own workspace pod — the web IDE, forwarded ports, and SSH — without exposing pods or spinning up per-workspace DNS, certs, and Ingress objects.
A workspace pod sits on a headless in-cluster Service and is never publicly exposed. ws-proxy is the single authenticated hop in front of the whole fleet: a request on <name>.ws.fastverk.com (or <port>-<name>.ws… for a forwarded port) is resolved to (name, port), matched to its DevWorkspace CR for the owner, and gated on your Cognito session — the sub in your id_token must equal spec.owner. Then it proxies through: plain HTTP, a WebSocket upgrade for the web IDE, or SSH-over-WebSocket at /__ssh for Cursor / VS Code Remote-SSH. Creating a workspace or forwarding a port mints no new networking — the wildcard absorbs it.
Creating a workspace or forwarding a port mints no new DNS, cert, or Ingress. The wildcard and this proxy absorb all of it.
Resolve, then authorize — every request.
For each request the proxy resolves the subdomain to a pod and makes one authorization decision. This is the decision it makes; the plugin ships no console panel — the table is illustrative.
| request | resolves to | gate | result |
|---|---|---|---|
| spurious-racoon.ws.fastverk.com | ws-spurious-racoon…:3000 | session + owner | VS Code |
| 3000-spurious-racoon.ws… | …:3000 (Public port) | public — exempt | no session needed |
| spurious-racoon.ws…/__ssh | …:22 (sshd) | session + owner | SSH-over-WS |
| spurious-racoon.ws… (not owner) | — | ownership | 403 |
| spurious-racoon.ws… (no session) | — | session | → console login |
Resolve → authorize → proxy → resume.
Four steps on every request, one hop.
Resolve
A request on <ws>.ws.fastverk.com hits the shared wildcard ALB → the proxy parses the host into (name, optional port), validates the name, and reads the DevWorkspace CR for spec.owner.
Authorize
A public port passes freely; otherwise it validates the Cognito id_token (RS256, JWKS cached with a kid-miss refresh) and requires sub == owner. A browser without a session is bounced to the console login; an API client gets 401/403.
Proxy
It dials the pod over in-cluster DNS and relays — plain HTTP, a WebSocket upgrade for the web IDE (101 Switching Protocols mirrored), or SSH-over-WebSocket at /__ssh. Cookie, Authorization, and Host are stripped; x-fastverk-user-sub/email are injected.
Resume
It stamps a throttled last-activity annotation for the idle-culler; if the pod is asleep it flips desired-state to Running and serves a branded, self-refreshing resuming page while it wakes.
The pod never sees your session.
Access control lives entirely at the edge — the workload stays oblivious to how you authenticated.
Four guarantees
- No pod is exposed: every workspace sits on a headless ClusterIP Service; the only way in is through this proxy, behind auth.
- Ownership is enforced per request: the Cognito sub in your session must equal the workspace's spec.owner — a mismatch is a hard 403, not a redirect.
- Credentials never reach the workload: the proxy strips Cookie, Authorization, and Host before forwarding, and injects only your identity headers.
- Three protocols, one edge: plain HTTP, the web IDE's WebSockets, and SSH-over-WebSocket for Remote-SSH — all through the same authenticated hop, kept in sync with the console's own token verification.
Scale the fleet, not the networking.
The alternative mints a DNS record, a cert, and an Ingress for every workspace — and asks you to secure each one.
The pod never sees your session credential. The proxy authenticates you, strips the secret, and forwards only who you are.
source · github.com/fastverk/plugin-ws-proxy
Prove it's safe to merge.
ws-proxy is one of 14 plugins in the fastverk console — hosted, or in your own cloud.