Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - eraow/boundary · GitHub
Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - eraow/boundary · GitHub
Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - eraow/boundary · GitHub
Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - eraow/boundary · GitHub
Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - eraow/boundary · GitHub
Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - eraow/boundary · GitHub
Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - eraow/boundary · GitHub
Skip to content

Repository files navigation

boundary

Network isolation tool for monitoring and restricting HTTP/HTTPS requests from processes.

boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.

Features

  • Process-level network isolation (Linux namespaces)
  • HTTP/HTTPS interception with transparent proxy and TLS certificate injection
  • Wildcard pattern matching for URL patterns
  • Request logging and monitoring
  • Linux support
  • Default deny-all security model

Installation

Quick Install (Recommended)

curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | bash

For installation options, manual installation, and release details, see RELEASES.md.

From Source

Build boundary from source:

# Clone the repository
git clone https://github.com/coder/boundary.git
cd boundary
# Build the binary
make build
# Install binary
sudo cp boundary /usr/local/bin/

Requirements:

  • Go 1.24 or later
  • Linux

Usage

Quick Start

When using the default nsjail backend, boundary escalates privileges automatically (via sudo and setpriv) to acquire the necessary capabilities:

boundary --allow "domain=github.com" -- curl https://github.com
boundary -- bash

Privilege escalation runs only when jail type is nsjail (the default). With landjail, no escalation is performed.

Examples

# Allow only requests to github.com
boundary --allow "domain=github.com" -- curl https://github.com
# Allow full access to GitHub issues API, but only GET/HEAD elsewhere on GitHub
boundary \
--allow "domain=github.com path=/api/issues/*" \
--allow "method=GET,HEAD domain=github.com" \
-- npm install
# Default deny-all: everything is blocked unless explicitly allowed
boundary -- curl https://example.com

Allow Rules

Format

--allow "key=value [key=value ...]"

Keys:

  • method - HTTP method(s), comma-separated (GET, POST, etc.)
  • domain - Domain/hostname pattern
  • path - URL path pattern(s), comma-separated

Examples

boundary --allow "domain=github.com" -- git pull
boundary --allow "domain=*.github.com" -- npm install # GitHub subdomains
boundary --allow "domain=github.com" --allow "domain=*.github.com" -- git pull # Both base domain and subdomains
boundary --allow "method=GET,HEAD domain=api.github.com" -- curl https://api.github.com
boundary --allow "method=POST domain=api.example.com path=/users,/posts" -- ./app # Multiple paths
boundary --allow "path=/api/v1/*,/api/v2/*" -- curl https://api.example.com/api/v1/users

Wildcards: * matches any characters. All traffic is denied unless explicitly allowed.

Logging

boundary --log-level warn --allow "domain=github.com" -- git pull # Default: only logs denied requests
boundary --log-level info --allow "method=*" -- npm install # Show all requests
boundary --log-level debug --allow "domain=github.com" -- git pull # Debug info

Log Levels:error, warn (default), info, debug

Audit Logs

Boundary tracks all HTTP/HTTPS requests that pass through the transparent proxy, recording whether each request was allowed or denied. This provides visibility into network access patterns for monitoring and compliance. By default, all requests are logged to stderr using structured logging.

Coder Integration

When running inside a Coder workspace, boundary can forward audit logs to the workspace agent, which then sends them to coderd for centralized logging. The intention is for these logs to work out of the box when an AI agent runs in a workspace using a module that has boundary enabled (e.g. the Claude Code module), and when boundary is used directly.

How it works:

  1. The workspace agent runs a Unix socket server at a configurable path (see: --log-proxy-socket-path)
  2. Boundary connects to this socket and streams audit event batches using a protobuf-based protocol
    • If the socket doesn't exist when boundary starts, a warning is logged to stderr and no audit logs are forwarded. This will occur on versions of coder that do not yet support forwarding boundary audit logs
  3. The workspace agent forwards these logs to coderd
  4. coderd emits the logs as structured log entries for ingestion by log aggregation systems

Platform Support

PlatformImplementationPrivileges
LinuxNetwork namespaces + iptablesCAP_NET_ADMIN (or root)
macOSNot supported-
WindowsNot supported-

Security and Privileges

All processes are expected to run as non-root users for security best practices:

  • boundary-parent: The main boundary process that sets up network isolation
  • boundary-child: The child process created within the network namespace
  • target/agent process: The command you're running (e.g., curl, npm, bash)

When using the nsjail backend (default), boundary escalates privileges itself: it re-executes via sudo and setpriv so that it runs with the minimum required capabilities (CAP_NET_ADMIN and optionally CAP_SYS_ADMIN for restricted environments) while still executing as your regular user.

Command-Line Options

boundary [flags] -- command [args...]
--config <PATH> Path to YAML config file (default: ~/.config/coder_boundary/config.yaml)
--allow <SPEC> Allow rule (repeatable). Merged with allowlist from config file
--log-level <LEVEL> Set log level (error, warn, info, debug). Default: warn
--log-dir <DIR> Directory to write logs to (default: stderr)
--proxy-port <PORT> HTTP proxy port (default: 8080)
--pprof Enable pprof profiling server
--pprof-port <PORT> pprof server port (default: 6060)
--disable-audit-logs Disable sending audit logs to the workspace agent
--log-proxy-socket-path <PATH> Path to the audit log socket
-h, --help Print help

Environment variables: BOUNDARY_CONFIG, BOUNDARY_ALLOW, BOUNDARY_LOG_LEVEL, BOUNDARY_LOG_DIR, PROXY_PORT, BOUNDARY_PPROF, BOUNDARY_PPROF_PORT, DISABLE_AUDIT_LOGS, CODER_AGENT_BOUNDARY_LOG_PROXY_SOCKET_PATH

Development

make build # Build for current platform
make build-all # Build for all platforms
make test# Run tests
make test-coverage # Run tests with coverage
make clean # Clean build artifacts
make fmt # Format code
make lint # Lint code

Architecture

For detailed information about how boundary works internally, see docs/architecture.md.

License

MIT License - see LICENSE file for details.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages