{"repo":"g0lab/g0efilter","free":true,"listed":false,"github":"https://github.com/g0lab/g0efilter","clone":"git clone https://github.com/g0lab/g0efilter.git","description":"Container Egress Traffic Filter with a GitHub Actions wrapper.","language":"Go","stars":10,"topics":["container","dashboard","go","network-filtering","traffic-filtering","alpine","egress-filtering","network-namespace","docker","kubernetes-controller"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"[!NOTE] Portions of this project were developed with the assistance of AI tools. [!WARNING] g0efilter is in active development. Its configuration is not stable yet. g0efilter controls network traffic leaving your containers. It runs beside a workload and applies IP and domain rules without decrypting TLS traffic. Features - Allow or block traffic by IP, CIDR, or domain. - Match exact domains, wildcards, or regular expressions. - Choose HTTPS inspection, DNS filtering, or strict DNS filtering. - Start with either a default-deny allowlist or a default-allow denylist. - Test and build policies with audit and learning modes. - Reload policies without restarting the container. - Use the optional dashboard, remote unblock, and alerts through shoutrrr. - Manage Kubernetes policies and inject sidecars with the optional controller. Quick start Create a policy directory: Add policy/policy.yaml : Save this as docker-compose.yaml : Start the services: See the examples for complete Compose files and policies. See the privilege model for how the container runs unprivileged with only NET ADMIN . Filter modes Attached containers share g0efilter's network namespace. Allowed IPs and CIDRs pass through directly. Other traffic is handled by FILTER MODE . Mode Checks domains at Blocks hardcoded IPs? Best for --- --- ---: --- https Connection time, using TLS SNI or the HTTP Host header Yes Precise control of web traffic dns DNS lookup time No Simple, broad filtering dns-strict DNS lookup and conne","default_branch":null,"files":null,"tree":[],"storefront":"/r/g0lab","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/g0lab/g0efilter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}