CargoWall
eBPF Firewall for GitHub Actions
Details
- External ID
- 47588383
- Source
- HN
- Company
- —
- Product
- CargoWall
- Website domain
- github.com
- Launched
- March 31, 2026
- Cohort
- —
- Upvotes
- 14
- Upvotes percentile
- 0.6758917589175891
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
We just open-sourced CargoWall - a lightweight eBPF firewall for GitHub Actions.We originally built it to stop LLM agents from connecting to untrusted domains. After recent GitHub Actions supply chain compromises like the Trivy attack, we realized it'd work well for blocking untrusted connections from CI runners too.It uses iptables DNAT to redirect all outbound port 53 traffic to a local DNS proxy, which checks each query against a hostname allowlist before forwarding. Resolved IPs from allowed responses are inserted into eBPF LPM trie maps, and a TC egress classifier attached to the network interface drops any packet whose destination IP/protocol/port isn't in the trie.Cgroup hooks capture every socket connect/sendmsg call system-wide, mapping the socket cookie to the process to correlate where connections are coming from. It then correlates the connection times with steps to provide a summary of which connections originated from which steps.ubuntu-latest and ubuntu-24.04 runners are supported. Simple one-step setup example: uses: code-cargo/cargowall-action@v1 # or v1.0.0 for immutable tag with: mode: enforce allowed-hosts: | registry.npmjs.org eBPF Program: https://github.com/code-cargo/cargowallGitHub Action: https://github.com/code-cargo/cargowall-actionWe'd love for you to give it a try! Happy to answer questions or take feedback.
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- ebpf firewall for github actions
- Manually corrected
- False
Could you build this?
No CargoWall is an eBPF-based network firewall operating inside Linux CI environments to inspect and drop untrusted outbound socket connections. Writing kernel-level eBPF probes, verifier-compliant C, and host security tooling requires specialized Linux kernel expertise.
What it would actually take: The project requires writing C programs for the Linux BPF virtual machine attached to network hook points (e.g., cgroup/sock_addr, tracepoints, or tc/XDP) that filter DNS requests and IP egress traffic. A user-space daemon (in Go or Rust via Cilium/ebpf or Aya) must load the eBPF bytecode into the kernel, populate BPF map rule tables with allowed domain/IP lists, and enforce policies inside ephemeral GitHub Actions container runners. This requires deep systems programming, Linux networking internals, and kernel security expertise.
Discussion
2 comments analyzed.
Concerns raised: CI/CD threat model is too optimistic, Network egress cost and friction in enterprise builds
Competitors
Other products that read as similar to this one — 160 launches clear the similarity bar, closest 8 shown.
Attention rank: #66 of 161 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 143 days after the earliest competitor.
- Netfence · hn · 2026-01-25 · 58 upvotes · similarity 0.56
- Dsnitch · hn · 2026-09-06 · 5 upvotes · similarity 0.55
- Cerberus · hn · 2025-12-20 · 12 upvotes · similarity 0.46
- Fence · hn · 2026-01-20 · 78 upvotes · similarity 0.45
- AIOStack · hn · 2026-01-14 · 9 upvotes · similarity 0.43
- PipeStep · hn · 2026-03-12 · 12 upvotes · similarity 0.43
- Hardened OpenClaw on AWS with Terraform · hn · 2026-03-13 · 10 upvotes · similarity 0.42
- Claw Patrol, a security firewall for agents · hn · 2026-06-09 · 112 upvotes · similarity 0.42
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.