content_proxy
A content-inspecting proxy in front of the browser. Ten-minute typical boot — joint slowest in the catalogue with docker.
create_node does not cover content_proxy. EC2__Platform._service_for raises NotImplementedError for everything but docker, podman and vnc. This spec creates nodes through its own CLI and service path, not the control-plane API. The generated CLI verbs below are real; the uniform API is not, for this spec.
The CLI, which nobody wrote
Per-spec CLIs are generated, not written. Spec__CLI__Builder registers the same verb set for every registered spec, so content_proxy gets its command surface from the same code that gives every other spec theirs:
# the uniform verb set, for every registered spec list · info · create · wait · health · connect · exec · delete · ami list|bake · cert # so, for this one sg content_proxy create --max-hours 1 sg content_proxy wait sg content_proxy health sg content_proxy delete
This is the strongest single argument that the thing is a platform rather than a service: adding a spec costs a manifest, a route class and a service — the CLI comes free. The three mechanisms →
What a node of this spec does
Every spec rides the same node lifecycle: a per-node API key minted and written to SSM before launch, composed user-data sections, EC2 tags as the registry, a two-phase health poll, then teardown. Teardown means terminate, not stop — systemd-run --on-active paired with InstanceInitiatedShutdownBehavior=terminate, on a default one-hour timer.