Netfence
Like Envoy for eBPF Filters
Details
- External ID
- 46754724
- Source
- HN
- Company
- —
- Product
- Netfence
- Website domain
- github.com
- Launched
- Jan. 25, 2026
- Cohort
- —
- Upvotes
- 58
- Upvotes percentile
- 0.8293807641633728
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
To power the firewalling for our agents so that they couldn't contact arbitrary services, I build netfence. It's like Envoy but for eBPF filters.It allows you to define different DNS-based rules that are resolved in a local daemon to IPs, then pushed to the eBPF filter to allow traffic. By doing it this way, we can still allow DNS-defined rules, but prevent contacting random IPs.There's also no network performance penalty, since it's just DNS lookups and eBPF filters referencing memory.It also means you don't have to tamper with the base image, which the agent could potentially manipulate to remove rules (unless you prevent root maybe).It automatically manages the lifecycle of eBPF filters on cgroups and interfaces, so it works well for both containers and micro VMs (like Firecracker).You implement a control plane, just like Envoy xDS, which you can manage the rules of each cgroup/interface. You can even manage DNS through the control plane to dynamically resolve records (which is helpful as a normal DNS server doesn't know which interface/cgroup a request might be coming from).We specifically use this to allow our agents to only contact S3, pip, apt, and npm.
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Horizontal
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- ebpf filtering for network traffic
- Manually corrected
- False
Could you build this?
No Developing an eBPF-based network firewall with dynamic user-space daemon rule compilation and kernel-space eBPF maps requires deep Linux kernel and networking engineering expertise.
What it would actually take: The architecture consists of a C/Rust eBPF kernel program hooked into TC (Traffic Control) or XDP network layers, interfacing via shared eBPF maps (like LPM trie) with a user-space control daemon written in Go/Rust (using cilium/ebpf or aya). The daemon must intercept DNS traffic, perform dynamic IP-to-domain mapping, handle DNS TTL expirations, and safely update kernel lookup tables without packet drops. This requires deep Linux kernel internals, low-level socket programming, and eBPF verifier navigation expertise.
Discussion
7 comments analyzed.
Competitors mentioned: Cilium (Kubernetes), Explicit HTTP proxies
Concerns raised: Latency of updating stale DNS caches on clients, Unclear positioning relative to Envoy xDS
Feature requests: Individual port-level allow/block rules
Competitors
Other products that read as similar to this one — 73 launches clear the similarity bar, closest 8 shown.
Attention rank: #14 of 74 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 75 days after the earliest competitor.
- CargoWall · hn · 2026-03-31 · 14 upvotes · similarity 0.56
- Dsnitch · hn · 2026-09-06 · 5 upvotes · similarity 0.50
- Claw Patrol, a security firewall for agents · hn · 2026-06-09 · 112 upvotes · similarity 0.45
- I built a firewall for agents because prompt engineering isn't security · hn · 2026-01-19 · 7 upvotes · similarity 0.45
- I built a smart proxy so your coding agent can run loose · hn · 2026-07-14 · 14 upvotes · similarity 0.44
- Cerberus · hn · 2025-12-20 · 12 upvotes · similarity 0.43
- Turn wire protocols into structured statements LLMs can understand · hn · 2026-09-10 · 6 upvotes · similarity 0.43
- Gecit · hn · 2026-04-05 · 9 upvotes · similarity 0.41
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.