

Sockguard
Like
Default-deny Docker and Podman socket proxy with body-aware policy enforcement, signed policies, rollout modes, rate limits, audit logs, and Prometheus metrics.
Cost / License
- Free
- Open Source (Apache-2.0)
Platforms
- Mac
- Linux
- Docker

Sockguard
Like
Features
- Docker Container
- Golang
Support for Docker
Sockguard News & Activities
Highlights All activities
Recent activities
Sockguard information
No comments or reviews, maybe you want to be first?
What is Sockguard?
Sockguard is a security-first Docker and Podman socket proxy written in Go. It sits between clients and the container engine, denies access by default, and filters API requests by method, path, request body, and response visibility. It supports signed policy bundles, per-profile audit, warn, and enforce rollout modes, hot reload, mTLS and Unix-socket isolation, rate limits, Prometheus metrics, and presets for tools such as Drydock, Portwing, Portainer, Watchtower, and CI runners. It is free and open source under the Apache-2.0 license.
