
iron-proxy
github.com/paradigmxyz/iron-proxy- Category
- Cybersecurity
- Rank
- No. 2147Tools index
Previous survey · No. 2135 ·
- Pricing
- Open Source
- Type
- TOOL
- Use case
- Security & Identity
- Builder
- @gakonst
- GitHub
- 686 stars
- Latest release
- v0.50.0
- Date
About
iron-proxy is a man-in-the-middle egress proxy that sits at the network boundary of untrusted workloads such as CI jobs, AI coding agents, and sandboxed containers. It enforces a default-deny policy so a workload can only reach explicitly allowlisted destinations, terminating TLS with on-the-fly certificates and shipping its own DNS server. Its distinguishing feature is boundary-level secret injection: the workload holds only a proxy token, and the real credential is swapped in after the request leaves the sandbox, with every request written to a structured audit log.
Why it made the leaderboard
Sandboxing agent network access and keeping real secrets out of the agent's reach is an unsolved operational problem for most teams running coding agents, and this is a deployable implementation rather than a policy document.
Tags
Tech Stack
Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.