CLI PROXY / SYSTEM PLAN REV 02

One server, seven engineers, one controlled AI account pool.

Claude, Grok and Codex CLI traffic is centralized on a single Ubuntu host. No provider OAuth credential is ever copied into an employee profile.

SSH trust boundary

  • U1
  • U2
  • U3
  • U4
  • U5
  • U6
  • U7

Seven isolated Linux profiles

CLIProxyAPI

127.0.0.1:8317

Local gateway · systemd

OAuth vault

  • Claude3 sessions
  • Grok3 sessions
  • Codex1 session

Readable only by the service account

No public listener. Every hop stays on the host.
Exposure
The gateway binds to loopback only. The admin UI is reached through ssh -L, never a public port.
Identity
One client key per Linux user. Any key can be revoked on its own without touching the others.
Routing
Round-robin across healthy credentials, one hour of session affinity, automatic failover.
Credentials
OAuth state lives in /var/lib/cliproxyapi/auth at 0700, owned by a locked service account.
Availability
systemd starts the service at boot and restarts it on crash. If the host is down, all seven stop together.

Configuration shape

host: "127.0.0.1"
port: 8317
auth-dir: "/var/lib/cliproxyapi/auth"

remote-management:
  allow-remote: false
  secret-key: "${MANAGEMENT_SECRET}"

api-keys:
  - "${USER_01_KEY}"
  - "… one per SSH user"

routing:
  strategy: "round-robin"
  session-affinity: true
  session-affinity-ttl: "1h"