Sockguard icon
Sockguard icon

Sockguard

Default-deny Docker and Podman socket proxy with body-aware policy enforcement, signed policies, rollout modes, rate limits, audit logs, and Prometheus metrics.

Sockguard product overview: control what reaches the Docker or Podman socket.

Cost / License

Platforms

  • Mac  Available through Homebrew; Docker Desktop or another supported Docker or Podman endpoint is required.
  • Linux  Native amd64 and arm64 binaries are available; Docker or Podman socket access is required.
  • Docker  Multi-architecture image for amd64 and arm64.
0likes
0comments
0alternatives
0articles

Features

  1.  Docker Container
  2.  Golang
  3. Docker icon  Support for Docker

Sockguard News & Activities

Highlights All activities

Recent activities

  • CodesWhat added Sockguard
  • POX updated Sockguard

Sockguard information

  • Developed by

    US flagCodesWhat
  • Licensing

    Open Source (Apache-2.0) and Free product.
  • Written in

  • Alternatives

    0 alternatives listed
  • Supported Languages

    • English

AlternativeTo Categories

DevelopmentSecurity & PrivacyNetwork & Admin

GitHub repository

  •  8 Stars
  •  0 Forks
  •  18 Open Issues
  •   Updated  
View on GitHub
Sockguard was added to AlternativeTo by CodesWhat on and this page was last updated .
No comments or reviews, maybe you want to be first?

What is Sockguard?

Sockguard is a security-first Docker and Podman socket proxy written in Go. It sits between clients and the container engine, denies access by default, and filters API requests by method, path, request body, and response visibility. It supports signed policy bundles, per-profile audit, warn, and enforce rollout modes, hot reload, mTLS and Unix-socket isolation, rate limits, Prometheus metrics, and presets for tools such as Drydock, Portwing, Portainer, Watchtower, and CI runners. It is free and open source under the Apache-2.0 license.

Official Links