Context
lean-grpc v1.2.0 made h2c truly Async under Std.Async (#6, docs/async-io.md). In-process TLS (native/tls_ffi.c / SSL_read / SSL_write) remains blocking FFI wrapped via AsyncByteTransport.ofBlocking.
Goal
End-to-end Async (or off-loop) TLS so serveTls / connectH2 do not stall the UV loop during handshake or byte IO.
Options to evaluate
- OpenSSL nonblocking BIO + integrate readiness with
Std.Async / libuv
- Off-loop worker pool for TLS read/write (keep BIO blocking off the UV thread)
- Hybrid: async TCP + TLS terminate in sidecar only (already optional via
LEAN_GRPC_TLS_PROXY)
Acceptance
- Documented Async TLS path (or explicit off-loop model) with no false “fully async TLS” claim until true
- Existing mTLS /
peerIdentity AuthN continues to work
- CI coverage (tlsLoopback + at least one concurrent Async+TLS smoke if on-loop)
Follow-up to #6 / #9.
Context
lean-grpc v1.2.0 made h2c truly Async under
Std.Async(#6, docs/async-io.md). In-process TLS (native/tls_ffi.c/SSL_read/SSL_write) remains blocking FFI wrapped viaAsyncByteTransport.ofBlocking.Goal
End-to-end Async (or off-loop) TLS so
serveTls/connectH2do not stall the UV loop during handshake or byte IO.Options to evaluate
Std.Async/ libuvLEAN_GRPC_TLS_PROXY)Acceptance
peerIdentityAuthN continues to workFollow-up to #6 / #9.