workspace access

Secure, per-user access to every workspace.

One long-lived proxy sits behind a single *.ws.fastverk.com wildcard and does the load-bearing work: resolve a subdomain to a workspace pod, check the session and ownership, and proxy HTTP, the web IDE's WebSockets, and SSH-over-WebSocket — without minting a single per-workspace DNS record, cert, or Ingress.

available
Resolves <name>.ws.fastverk.com to the right podGates on the Cognito session + workspace ownershipProxies HTTP, IDE WebSockets, and SSH-over-WebSocketStrips your credentials before they reach the podOne wildcard for the whole fleet — no per-workspace Ingress
one wildcard
for the whole fleet
*.ws.fastverk.com · no per-workspace DNS/cert/Ingress
session + owner
gated at the edge
Cognito id_token · sub == spec.owner
HTTP · WS · SSH
one proxy, three protocols
web IDE + Remote-SSH
0
credentials reach the pod
Cookie / Authorization stripped
why it exists

One proxy, not an Ingress per workspace.

Give every developer private access to their own workspace pod — the web IDE, forwarded ports, and SSH — without exposing pods or spinning up per-workspace DNS, certs, and Ingress objects.

A workspace pod sits on a headless in-cluster Service and is never publicly exposed. ws-proxy is the single authenticated hop in front of the whole fleet: a request on <name>.ws.fastverk.com (or <port>-<name>.ws… for a forwarded port) is resolved to (name, port), matched to its DevWorkspace CR for the owner, and gated on your Cognito session — the sub in your id_token must equal spec.owner. Then it proxies through: plain HTTP, a WebSocket upgrade for the web IDE, or SSH-over-WebSocket at /__ssh for Cursor / VS Code Remote-SSH. Creating a workspace or forwarding a port mints no new networking — the wildcard absorbs it.

Creating a workspace or forwarding a port mints no new DNS, cert, or Ingress. The wildcard and this proxy absorb all of it.

plugin-ws-proxy · the load-bearing edge
what the edge decides

Resolve, then authorize — every request.

For each request the proxy resolves the subdomain to a pod and makes one authorization decision. This is the decision it makes; the plugin ships no console panel — the table is illustrative.

access decision
parse host → resolve DevWorkspace → authorize
requestresolves togateresult
spurious-racoon.ws.fastverk.com ws-spurious-racoon…:3000 session + owner VS Code
3000-spurious-racoon.ws… …:3000 (Public port) public — exempt no session needed
spurious-racoon.ws…/__ssh …:22 (sshd) session + owner SSH-over-WS
spurious-racoon.ws… (not owner) — ownership 403
spurious-racoon.ws… (no session) — session → console login
browser: redirects to loginapi client: 401 / 403
the flow

Resolve → authorize → proxy → resume.

Four steps on every request, one hop.

01

Resolve

A request on <ws>.ws.fastverk.com hits the shared wildcard ALB → the proxy parses the host into (name, optional port), validates the name, and reads the DevWorkspace CR for spec.owner.

02

Authorize

A public port passes freely; otherwise it validates the Cognito id_token (RS256, JWKS cached with a kid-miss refresh) and requires sub == owner. A browser without a session is bounced to the console login; an API client gets 401/403.

03

Proxy

It dials the pod over in-cluster DNS and relays — plain HTTP, a WebSocket upgrade for the web IDE (101 Switching Protocols mirrored), or SSH-over-WebSocket at /__ssh. Cookie, Authorization, and Host are stripped; x-fastverk-user-sub/email are injected.

04

Resume

It stamps a throttled last-activity annotation for the idle-culler; if the pod is asleep it flips desired-state to Running and serves a branded, self-refreshing resuming page while it wakes.

how it's safe

The pod never sees your session.

Access control lives entirely at the edge — the workload stays oblivious to how you authenticated.

Four guarantees

  • No pod is exposed: every workspace sits on a headless ClusterIP Service; the only way in is through this proxy, behind auth.
  • Ownership is enforced per request: the Cognito sub in your session must equal the workspace's spec.owner — a mismatch is a hard 403, not a redirect.
  • Credentials never reach the workload: the proxy strips Cookie, Authorization, and Host before forwarding, and injects only your identity headers.
  • Three protocols, one edge: plain HTTP, the web IDE's WebSockets, and SSH-over-WebSocket for Remote-SSH — all through the same authenticated hop, kept in sync with the console's own token verification.
vs an Ingress each

Scale the fleet, not the networking.

The alternative mints a DNS record, a cert, and an Ingress for every workspace — and asks you to secure each one.

fastverk ws-proxy
per-workspace Ingress
New workspace cost
✓ Zero new infra — the wildcard absorbs it
A DNS record, a cert, an Ingress each
Access control
✓ Session + ownership at the edge
Roll your own per-service auth
Protocols
✓ HTTP + WS + SSH over one hop
Separate paths, separately secured
Pod exposure
✓ Never — proxy-only
A public endpoint per workspace
Idle
✓ Stamps activity + wakes on access
Always-on or manual

The pod never sees your session credential. The proxy authenticates you, strips the secret, and forwards only who you are.

plugin-ws-proxy · auth at the edge

source · github.com/fastverk/plugin-ws-proxy

Prove it's safe to merge.

ws-proxy is one of 14 plugins in the fastverk console — hosted, or in your own cloud.