MtlsTunnel 0.1.0-alpha.1
dotnet add package MtlsTunnel --version 0.1.0-alpha.1
NuGet\Install-Package MtlsTunnel -Version 0.1.0-alpha.1
<PackageReference Include="MtlsTunnel" Version="0.1.0-alpha.1" />
<PackageVersion Include="MtlsTunnel" Version="0.1.0-alpha.1" />
<PackageReference Include="MtlsTunnel" />
paket add MtlsTunnel --version 0.1.0-alpha.1
#r "nuget: MtlsTunnel, 0.1.0-alpha.1"
#:package MtlsTunnel@0.1.0-alpha.1
#addin nuget:?package=MtlsTunnel&version=0.1.0-alpha.1&prerelease
#tool nuget:?package=MtlsTunnel&version=0.1.0-alpha.1&prerelease
MtlsTunnel
An alpha library by doothejob for .NET 10. Creates a bounded loopback listener inside the application and carries each physical connection over its own TLS 1.3 mutually authenticated stream. Direct TCP is the default. This package has no SQL, WebSocket, Cloudflare, hosting or Docker dependency. It does not interpret SQL or retry interrupted writes.
Call await Tunnel.StartAsync(TunnelOptions, cancellationToken), use LocalEndpoint
for the application connection, and await DisposeAsync() at application shutdown.
Supply GatewayHost, GatewayPort, the certificate's expected GatewayName,
ClientCertificate with its private key, and ServerRootCertificate. The tunnel clones
the certificates; the caller owns the supplied objects. Cancellation governs the tunnel
lifetime. Resource and handshake limits remain configurable through TunnelOptions.
SQL consumers separately reference official Microsoft.Data.SqlClient and retain
Encrypt=True, TrustServerCertificate=False, HostNameInCertificate, and SQL CA trust.
Keep the tunnel alive across pooled SQL operations; close work and clear only your own
pool before disposing the tunnel. Other local processes may reach its loopback listener.
Built and executed on Linux x64 with .NET 10. Windows, ARM, AOT and trimming are not validated. Certificate revocation checking is not implemented. This is a validated PoC, not an unlimited production stability or security audit claim.
Complete package-based samples and instructions are in samples/dotnet/ and
docs/dotnet-sdk.md in the private repository. Source:
https://bitbucket.org/remixed2/mssql-cloudflare
Install the direct transport without the optional layers:
dotnet add package MtlsTunnel --version 0.1.0-alpha.1
Author and copyright holder: doothejob. Licensing is declared in the package metadata.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- No dependencies.
NuGet packages (1)
Showing the top 1 NuGet packages that depend on MtlsTunnel:
| Package | Downloads |
|---|---|
|
MtlsTunnel.WebSockets
Bounded in-process mutually authenticated TLS transport for .NET 10. See the package README for layer-specific behavior and alpha limitations. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.0-alpha.1 | 63 | 9/21/2026 |
Initial alpha with direct TCP, optional WebSocket and Cloudflare layers, strict mTLS validation, bounded relay and typed final-close diagnostics.