Vibeleaderboard
Index / tool
Visit github.com
Category
Cybersecurity
Rank
No. 2147Tools index

Previous survey · No. 2135 ·

Pricing
Open Source
Type
TOOL
Use case
Security & Identity
Builder
@gakonst
GitHub
686 stars
Latest release
v0.50.0
Date

About

iron-proxy is a man-in-the-middle egress proxy that sits at the network boundary of untrusted workloads such as CI jobs, AI coding agents, and sandboxed containers. It enforces a default-deny policy so a workload can only reach explicitly allowlisted destinations, terminating TLS with on-the-fly certificates and shipping its own DNS server. Its distinguishing feature is boundary-level secret injection: the workload holds only a proxy token, and the real credential is swapped in after the request leaves the sandbox, with every request written to a structured audit log.

Why it made the leaderboard

Sandboxing agent network access and keeping real secrets out of the agent's reach is an unsolved operational problem for most teams running coding agents, and this is a deployable implementation rather than a policy document.

Tags

egress-proxynetwork-securitysandboxingcisecretsgoaudit-logging

Tech Stack

Go

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.