| Goal | MITM? | Listeners | Key configuration | CA install? |
|---|---|---|---|---|
| Policy proxy | No | explicit | mitm:false, http[] |
No |
| Egress firewall / SSRF guard | No | explicit | egress[], deny first |
No |
| Authenticated proxy | Optional | explicit | auth.http_proxy |
Only with MITM |
| Inject credentials | Yes | explicit or transparent | header.fetch |
Yes |
| Block, rewrite, redact | Usually | explicit or transparent | request/response actions | Yes for HTTPS |
| Contain an agent | Optional | either | narrow http[] + egress[] |
Only with MITM |
| Intercept without client proxy settings | Optional | REDIRECT or TPROXY | nftables + policy routing | Only with MITM |
| Central broker policy | Yes | either | webhook |
Yes for HTTPS |
| Inspect TLS | Yes | either | MITM + telemetry | Yes |
Start with the Docker egress allowlist tutorial if you want a result without distributing a CA.