Goal MITM? Listeners Key configuration CA install?
Policy proxy No explicit mitm:false, http[] No
Egress firewall / SSRF guard No explicit egress[], deny first No
Authenticated proxy Optional explicit auth.http_proxy Only with MITM
Inject credentials Yes explicit or transparent header.fetch Yes
Block, rewrite, redact Usually explicit or transparent request/response actions Yes for HTTPS
Contain an agent Optional either narrow http[] + egress[] Only with MITM
Intercept without client proxy settings Optional REDIRECT or TPROXY nftables + policy routing Only with MITM
Central broker policy Yes either webhook Yes for HTTPS
Inspect TLS Yes either MITM + telemetry Yes

Start with the Docker egress allowlist tutorial if you want a result without distributing a CA.