Policy
URL-category policy is two text files, wired as NixOS options and baked into the container images:
| File | Meaning |
|---|---|
nix/policy/pass.txt |
splice — never decrypted, flows through untouched |
nix/policy/bump.txt |
decrypt + ClamAV scan always |
Unmatched domains default to bump (fail closed). Order is passlist → bumplist → default.
Format
One domain per line; the addon matches hostnames and SNI:
# nix/policy/pass.txt
bank.example.com
eu-identity-gov-portal.gov
# nix/policy/bump.txt
facebook.com
*.facebook.com
Overriding
NixOS appliance — policy is a rebuild-time option:
services.opensase.policyPass = ./my/pass.txt;
services.opensase.policyBump = ./my/bump.txt;Containers — the lists are baked in per image tag. To change policy, rebuild the opensase-mitmproxy image with your lists (they are nix/policy/* store paths in nix/images.nix), or edit the addon invocation in the entrypoint to point at mounted files.
Swapping in a URL-categorization feed
The addon’s request hook reads the two lists into a verdict function: classify(host) -> "pass" | "bump". Pointing classify at a live URL-categorization API instead of static files is the planned v2 change — verdicts, logging, and scanning are unaffected.
Reading verdicts
docker compose -p opensase exec mitmproxy tail -f /data/log/decisions.jsonl
# appliance:
journalctl -u opensase-proxy -f
tail -f /var/lib/opensase/log/decisions.jsonlEach line: timestamp, host, category, action (splice/bump), scan verdict (clean/INFECTED).