Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Netfence

Like Envoy for eBPF Filters

Details

External ID
46754724
Source
HN
Company
—
Product
Netfence
Website domain
github.com
Launched
Jan. 25, 2026
Cohort
—
Upvotes
58
Upvotes percentile
0.8293807641633728
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

To power the firewalling for our agents so that they couldn't contact arbitrary services, I build netfence. It's like Envoy but for eBPF filters.It allows you to define different DNS-based rules that are resolved in a local daemon to IPs, then pushed to the eBPF filter to allow traffic. By doing it this way, we can still allow DNS-defined rules, but prevent contacting random IPs.There's also no network performance penalty, since it's just DNS lookups and eBPF filters referencing memory.It also means you don't have to tamper with the base image, which the agent could potentially manipulate to remove rules (unless you prevent root maybe).It automatically manages the lifecycle of eBPF filters on cgroups and interfaces, so it works well for both containers and micro VMs (like Firecracker).You implement a control plane, just like Envoy xDS, which you can manage the rules of each cgroup/interface. You can even manage DNS through the control plane to dynamically resolve records (which is helpful as a normal DNS server doesn't know which interface/cgroup a request might be coming from).We specifically use this to allow our agents to only contact S3, pip, apt, and npm.

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Horizontal
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
ebpf filtering for network traffic
Manually corrected
False

Could you build this?

No Developing an eBPF-based network firewall with dynamic user-space daemon rule compilation and kernel-space eBPF maps requires deep Linux kernel and networking engineering expertise.

What it would actually take: The architecture consists of a C/Rust eBPF kernel program hooked into TC (Traffic Control) or XDP network layers, interfacing via shared eBPF maps (like LPM trie) with a user-space control daemon written in Go/Rust (using cilium/ebpf or aya). The daemon must intercept DNS traffic, perform dynamic IP-to-domain mapping, handle DNS TTL expirations, and safely update kernel lookup tables without packet drops. This requires deep Linux kernel internals, low-level socket programming, and eBPF verifier navigation expertise.

Discussion

7 comments analyzed.

Competitors mentioned: Cilium (Kubernetes), Explicit HTTP proxies

Concerns raised: Latency of updating stale DNS caches on clients, Unclear positioning relative to Envoy xDS

Feature requests: Individual port-level allow/block rules

Competitors

Other products that read as similar to this one — 73 launches clear the similarity bar, closest 8 shown.

Attention rank: #14 of 74 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 75 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.