Real hardware surfaced this: H2C failed with 'IP address mismatch', not a chain-of-trust error like P1P's 'self-signed certificate'. Bambu printer certs don't carry their DHCP-assigned LAN IP as a SAN, so native-tls's default hostname check will never pass against a real printer. Added danger_accept_invalid_hostnames(true) unconditionally in build_connector() — this only skips the SAN/IP match, it's independent from danger_accept_invalid_certs (chain trust), which stays fully enforced for BundledCa/Custom. Verified both directions against local test servers, not just compiled: - a cert signed by a trusted CA, with a SAN that does NOT match the connecting IP, now verifies OK (previously failed exactly like H2C did) - a cert signed by an UNTRUSTED CA still correctly fails verification, confirming this change didn't weaken chain-of-trust checking
continuum-proxy
Edge gateway daemon for the Continuum print farm platform. Runs on a Linux
SBC on-site, talks to printers over the LAN, and keeps a connection to the
cloud control plane (continuum-backend).
This is a learning-stage boilerplate
This repo is deliberately minimal right now — real printer protocol clients
(Bambu MQTT+FTPS, PrusaLink REST, Klipper/Moonraker WebSocket) are not
implemented yet. Each vendor is a stub that just prints what it would do
(src/printer/bambu.rs, prusa.rs, klipper.rs). The idea is to learn
Rust's polymorphism pattern (trait + enum, since Rust has no class
inheritance) on something simple before adding real networking on top.
Getting started
cp .env.example .env
cargo run # the daemon: cloud uplink + go2rtc watchdog
cargo run --example printer_polymorphism # standalone demo, no network/env needed
cp printers.example.toml printers.toml # fill in your real printers (gitignored)
cargo run --example test_bambu_certs # real TLS handshake test against each Bambu printer
Structure
src/
main.rs Runs the uplink and the go2rtc watchdog side by side
config.rs Loads settings from environment variables
fleet.rs Loads printers.toml into ready-to-use PrinterHandles
uplink/ WebSocket client to continuum-backend: connect, heartbeat, reconnect on drop
printer/ GenericPrinter trait + PrinterBase + PrinterHandle enum + one stub per vendor
go2rtc.rs Restarts the go2rtc camera-restreaming process if it dies
examples/
printer_polymorphism.rs Runs all five printer stubs through one `connect()` call site
test_bambu_certs.rs Loads printers.toml, does a real TLS handshake to each Bambu printer
src/printer/ is where the "inheritance" question lives — see that
module's doc comment for the trait+enum pattern this project uses instead
of class inheritance, and run printer_polymorphism to see it work.
printers.toml (gitignored — copy from printers.example.toml) holds real
per-printer connection details: host, access code, and — since not every
Bambu printer trusts the same certificate (see certs/README.md) — an
optional per-printer CA override. src/fleet.rs loads it; nothing in
main.rs uses it yet, but test_bambu_certs does, as a real (if narrow —
just the TLS handshake, no MQTT) way to check a printer's certificate
without needing the full MQTT client built yet.
What's not here yet (on purpose)
- Real MQTT/FTPS/HTTP/WebSocket printer clients —
src/printer/*.rshas aprintln!where each of these will go. - Local SQLite buffering for telemetry across connectivity gaps.
- LAN printer discovery (SSDP/mDNS).
- The mechanical plate-changer interface (serial/GPIO).
Add these back in one at a time as you get comfortable with the Rust underneath them — each is its own small lesson (async I/O, a new crate's API, error handling for a real protocol) rather than something to absorb all at once.