Fence
Sandbox CLI commands with network/filesystem restrictions
Details
- External ID
- 46695467
- Source
- HN
- Company
- —
- Product
- Fence
- Website domain
- github.com
- Launched
- Jan. 20, 2026
- Cohort
- —
- Upvotes
- 78
- Upvotes percentile
- 0.8728590250329381
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Hi HN!Fence wraps any command in a sandbox that blocks network by default and restricts filesystem writes. Useful for running semi-trusted code (package installs, build scripts, unfamiliar repos) with controlled side effects, or even just blocking tools that phone home.> fence curl https://example.com # -> blocked> fence -t code -- npm install # -> template with registries allowed> fence -m -- npm install # -> monitor mode: see what gets blockedOne use-case is to use it with AI coding agents to reduce the risk of running agents with fewer interactive permission prompts:> fence -t code -- claude --dangerously-skip-permissionsYou can import existing Claude Code permissions with `fence import --claude`.Fence uses OS-native sandboxing (macOS sandbox-exec, Linux bubblewrap) + local HTTP/SOCKS proxies for domain filtering.Why I built this: I work on Tusk Drift, a system to record and replay real traffic as API tests (https://github.com/Use-Tusk/tusk-drift-cli). I needed a way to sandbox the service under test during replays to block localhost outbound connections (Postgres, Redis) and force the app to use mocks instead of real services. I quickly realized that this could be a general purpose tool that would also be useful as a permission manager across CLI agents.Limitations: Not strong containment against malware. Proxy-based filtering requires programs to respect `HTTP_PROXY`.Curious if others have run into similar needs, and happy to answer any questions!
Enrichment
- Theme
- Claude integrations and coding agents
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- sandboxed cli command execution with restrictions
- Manually corrected
- False
Could you build this?
Partial A basic CLI wrapper is easy to vibe code, but low-level sandbox isolation of arbitrary binaries across OS platforms requires deep operating system security internals.
What it would actually take: Fence must leverage OS-native isolation primitives: Linux namespaces, cgroups, and seccomp-bpf filters (or `landlock`), and macOS Sandbox (`sandbox-exec` / seatbelt APIs or Endpoint Security framework). Implementing granular network interception and filesystem cow/virtualization without requiring root access requires low-level C or Rust systems programming.
Discussion
20 comments analyzed.
Competitors mentioned: sandbox-runtime (Anthropic), sandvault (MacOS limited user account approach), clodpod (MacOS virtual machine approach), Steam pressure-vessel containers
Concerns raised: Nested bubblewrap sandboxes don't work (namespace nesting limitations), Domain filtering relies on HTTP_PROXY (malware could ignore it), OS sandboxes aren't VM-level isolation (kernel exploits possible), No resource limits or content inspection, Uncertainty about Fargate/ECS/Lambda deployment support
Feature requests: Deny-by-default read access mode with system path allowlist, Resource limits (CPU, memory, fork bomb protection), Extend to API calls and token budget restrictions, Clearer macOS documentation in README
Competitors
Other products that read as similar to this one — 215 launches clear the similarity bar, closest 8 shown.
Attention rank: #33 of 216 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 83 days after the earliest competitor.
- Zerobox · hn · 2026-03-30 · 141 upvotes · similarity 0.53
- A context-aware permission guard for Claude Code · hn · 2026-03-11 · 127 upvotes · similarity 0.51
- Bx · hn · 2026-04-07 · 8 upvotes · similarity 0.48
- Claw Patrol, a security firewall for agents · hn · 2026-06-09 · 112 upvotes · similarity 0.46
- CapLock · ph · 2026-09-28 · 1 upvotes · similarity 0.45
- CargoWall · hn · 2026-03-31 · 14 upvotes · similarity 0.45
- Tui2web · hn · 2026-09-25 · 7 upvotes · similarity 0.44
- I built a smart proxy so your coding agent can run loose · hn · 2026-07-14 · 14 upvotes · similarity 0.44
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.