refactor: rewrite tunnel system with host-network cloudflared containers

Replace the subprocess-based tunnel implementation with Docker containers
running on the host network. This eliminates all container name resolution
bugs that caused tunnel 502 errors.

New design:
- Each tunnel is a docker run --network host cloudflare/cloudflared container
- cloudflared connects to localhost:{published_port} (Docker port forwarding)
- No dependency on container names, backend network DNS, or binding diagnostics
- Tunnels named predictably: tunnel-{instance_name}
- Start/stop/recreate use container names instead of PIDs

Files changed:
- NEW: apps/api/src/services/tunnel.py — clean tunnel module (start/stop/recreate/health)
- apps/api/src/services/docker.py — removed 250 lines of old tunnel code
- apps/api/src/api/tool_instances.py — use new tunnel module, store container_name
- apps/api/src/services/health_monitor.py — updated import
- apps/web/src/components/session-card.tsx — Recreate Tunnel button always visible

Quality gates: ruff clean, 13 tests passed (health_monitor + notifications)
This commit is contained in:
2026-05-30 12:28:54 +02:00
parent 401ad2e65d
commit 6cf06d2380
5 changed files with 249 additions and 375 deletions
+1 -1
View File
@@ -333,7 +333,7 @@ export function SessionCard({
onClick: () => onRecreateTunnel(session),
},
]
: []),
: []),
...(isActive && onStop
? [
{