Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

CargoWall

eBPF Firewall for GitHub Actions

Details

External ID
47588383
Source
HN
Company
—
Product
CargoWall
Website domain
github.com
Launched
March 31, 2026
Cohort
—
Upvotes
14
Upvotes percentile
0.6758917589175891
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

We just open-sourced CargoWall - a lightweight eBPF firewall for GitHub Actions.We originally built it to stop LLM agents from connecting to untrusted domains. After recent GitHub Actions supply chain compromises like the Trivy attack, we realized it'd work well for blocking untrusted connections from CI runners too.It uses iptables DNAT to redirect all outbound port 53 traffic to a local DNS proxy, which checks each query against a hostname allowlist before forwarding. Resolved IPs from allowed responses are inserted into eBPF LPM trie maps, and a TC egress classifier attached to the network interface drops any packet whose destination IP/protocol/port isn't in the trie.Cgroup hooks capture every socket connect/sendmsg call system-wide, mapping the socket cookie to the process to correlate where connections are coming from. It then correlates the connection times with steps to provide a summary of which connections originated from which steps.ubuntu-latest and ubuntu-24.04 runners are supported. Simple one-step setup example: uses: code-cargo/cargowall-action@v1 # or v1.0.0 for immutable tag with: mode: enforce allowed-hosts: | registry.npmjs.org eBPF Program: https://github.com/code-cargo/cargowallGitHub Action: https://github.com/code-cargo/cargowall-actionWe'd love for you to give it a try! Happy to answer questions or take feedback.

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
ebpf firewall for github actions
Manually corrected
False

Could you build this?

No CargoWall is an eBPF-based network firewall operating inside Linux CI environments to inspect and drop untrusted outbound socket connections. Writing kernel-level eBPF probes, verifier-compliant C, and host security tooling requires specialized Linux kernel expertise.

What it would actually take: The project requires writing C programs for the Linux BPF virtual machine attached to network hook points (e.g., cgroup/sock_addr, tracepoints, or tc/XDP) that filter DNS requests and IP egress traffic. A user-space daemon (in Go or Rust via Cilium/ebpf or Aya) must load the eBPF bytecode into the kernel, populate BPF map rule tables with allowed domain/IP lists, and enforce policies inside ephemeral GitHub Actions container runners. This requires deep systems programming, Linux networking internals, and kernel security expertise.

Discussion

2 comments analyzed.

Concerns raised: CI/CD threat model is too optimistic, Network egress cost and friction in enterprise builds

Competitors

Other products that read as similar to this one — 160 launches clear the similarity bar, closest 8 shown.

Attention rank: #66 of 161 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 143 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.