{"repo":"palkeo/foreman","free":true,"listed":false,"github":"https://github.com/palkeo/foreman","clone":"git clone https://github.com/palkeo/foreman.git","description":"A secure self-hosted agent orchestrator.","language":"Python","stars":15,"topics":[],"license":null,"category":"self-hosted-apps","readme_excerpt":"Foreman A secure orchestrator for running short-lived interactive LLM sessions in sandboxed Incus containers. It is designed to be self-hosted. Read the blog post for a high-level overview of what this project is. What it does - Sandboxes agents in ephemeral Incus containers or VMs with full root access: agents can do anything inside. - Intercepts all network traffic through a MITM proxy that controls access per domain, path, and HTTP method. The proxy strips headers to minimize side-channels. - Injects secrets transparently : agents never see API keys or tokens. The proxy adds real credentials to outgoing requests, so even a compromised agent can't exfiltrate them. - Connects to chat platforms and forges (Telegram, Signal, web UI, Forgejo...) so you can talk to agents from your phone and run many in parallel. - Logs everything : all LLM thoughts, tool calls, and network activity are persisted as structured session logs, and can be made available to future agents for introspection and self-improvement. What it does not do - Implement its own agent loop: it runs Claude Code, OpenCode, or whatever you want inside containers. - Reinvent sandboxing: Incus handles the containers/VMs. Foreman handles orchestration, networking, and secrets. How it works Sessions & Lifecycle Sessions are ephemeral instances (container or VMs). Each session has an associated name ( default-web-84 ) and ephemeral secret. The secret is used to authenticate to Foreman. Each session runs in an ephemeral I","default_branch":null,"files":null,"tree":[],"storefront":"/r/palkeo","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/palkeo/foreman/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}