- [ ] Block direct workload egress at the firewall.
- [ ] Keep the control API on a mode-restricted Unix socket.
- [ ] Keep the seeded deny-first egress ranges or tighten them.
- [ ] End
egress[]deliberately; fall-through denies. - [ ] Put narrow connection and message rules before broad ones.
- [ ] Treat
mitm:falseas full encrypted tunnel authority. - [ ] Require proxy auth where network source identity is insufficient.
- [ ] Restrict
--trusted-proxiesand sanitize forwarded identity headers. - [ ] Scope broker sockets, destinations, fields, concurrency, and cache policy.
- [ ] Leave
failOpenfalse unless availability explicitly outweighs containment. - [ ] Never permit brokers to inject framing, hop-by-hop, or proxy-auth headers.
- [ ] Keep
clusterKeyseparate from Storage and backups. - [ ] Alert on forwarding denials, auth failures, broker failures, and rule compile errors.
Concepts
Use cases
- Overview
- Policy proxy without MITM
- Block ads and trackers without MITM
- Egress firewall & SSRF guard
- Authenticating forward proxy
- Header & credential injection
- Block, rewrite, redact
- Agent / sandbox containment
- Transparent interception (TPROXY/REDIRECT)
- Central policy via broker
- Debugging & inspecting TLS
Tutorials
Configuration
Operations
Security
On This Page