frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Netfence – Like Envoy for eBPF Filters

https://github.com/danthegoodman1/netfence
8•dangoodmanUT•1h ago
To power the firewalling for our agents so that they couldn't contact arbitrary services, I build netfence. It's like Envoy but for eBPF filters.

It allows you to define different DNS-based rules that are resolved in a local daemon to IPs, then pushed to the eBPF filter to allow traffic. By doing it this way, we can still allow DNS-defined rules, but prevent contacting random IPs.

There's also no network performance penalty, since it's just DNS lookups and eBPF filters referencing memory.

It also means you don't have to tamper with the base image, which the agent could potentially manipulate to remove rules (unless you prevent root maybe).

It automatically manages the lifecycle of eBPF filters on cgroups and interfaces, so it works well for both containers and micro VMs (like Firecracker).

You implement a control plane, just like Envoy xDS, which you can manage the rules of each cgroup/interface. You can even manage DNS through the control plane to dynamically resolve records (which is helpful as a normal DNS server doesn't know which interface/cgroup a request might be coming from).

We specifically use this to allow our agents to only contact S3, pip, apt, and npm.

Show HN: Bonsplit – Tabs and splits for native macOS apps

https://bonsplit.alasdairmonk.com
112•sgottit•4h ago•15 comments

Show HN: Netfence – Like Envoy for eBPF Filters

https://github.com/danthegoodman1/netfence
8•dangoodmanUT•1h ago•0 comments

Show HN: TUI for managing XDG default applications

https://github.com/mitjafelicijan/xdgctl
56•mitjafelicijan•5h ago•18 comments

Show HN: Bucket – Encrypted file sharing for people who live in the terminal

https://bucketlabs.org
4•bucket_•53m ago•2 comments

Show HN: LangGraph architecture that scales (hexagonal pattern, 110 tests)

https://github.com/cleverhoods/sagecompass
7•cleverhoods•5d ago•0 comments

Show HN: AutoShorts – Local, GPU-accelerated AI video pipeline for creators

https://github.com/divyaprakash0426/autoshorts
57•divyaprakash•9h ago•25 comments

Show HN: Generate the perfect kickoff prompt

https://vibeprompting.dev
2•relatedcode•1h ago•0 comments

Show HN: Open Computer-Animated Multivariable Calculus Course in 6 Languages

https://calculus.academa.ai/
3•sinaatalay•1h ago•0 comments

Show HN: Free PDF Editor by TechRex – client-side PDF editing, OCR, compression

https://pdffreeeditor.com/
3•Maaz-Sohail•1h ago•0 comments

Show HN: AI powered daily tracker of the US slide into authoritarianism

https://www.worstdaysofar.com/
2•locallyoptimal•1h ago•0 comments

Show HN: Sightline – Shodan-style search for real-world infra using OSM Data

https://github.com/ni5arga/sightline
14•ni5arga•8h ago•0 comments

Show HN: LLMNet – The Offline Internet, Search the web without the web

https://github.com/skorotkiewicz/llmnet
3•modinfo•2h ago•1 comments

Show HN: HomeGenGuide – Calculator for home generator installation costs

https://www.home-generator-installation.com
3•vansxxx•3h ago•0 comments

Show HN: C From Scratch – Learn safety-critical C with prove-first methodology

https://github.com/SpeyTech/c-from-scratch
47•william1872•16h ago•5 comments

Show HN: Waves – Terminal music player with download, tagging, and library

https://github.com/llehouerou/waves
2•llehouerou•4h ago•0 comments

Show HN: Open-source Figma design to code

https://github.com/vibeflowing-inc/vibe_figma
48•alepeak•1d ago•8 comments

Show HN: First Valkey-specific VS Code extension (open source Redis fork)

https://github.com/BetterDB-inc/vscode
2•kaliades•4h ago•6 comments

Show HN: VM-curator – a TUI alternative to libvirt and virt-manager

https://github.com/mroboff/vm-curator
36•theYipster•13h ago•7 comments

Show HN: StormWatch – Weather emergency dashboard with prep checklists

https://jeisey.github.io/stormwatch/
42•lotusxblack•21h ago•9 comments

Show HN: Coi – A language that compiles to WASM, beats React/Vue

210•io_eric•4d ago•67 comments

Show HN: Sara – Markdown-based requirements traceability tool written in Rust

https://github.com/cledouarec/sara
3•cledouarec•6h ago•2 comments

Show HN: Semantic search engine for Studio Ghibli movie

https://ghibli-search.anini.workers.dev/
42•aninibread•4d ago•10 comments

Show HN: isometric.nyc – giant isometric pixel art map of NYC

https://cannoneyed.com/isometric-nyc/
1302•cannoneyed•2d ago•240 comments

Show HN: Polymcp – Turn Any Python Function into an MCP Tool for AI Agents

22•justvugg•21h ago•6 comments

Show HN: Text-to-video model from scratch (2 brothers, 2 years, 2B params)

https://huggingface.co/collections/Linum-AI/linum-v2-2b-text-to-video
156•schopra909•3d ago•24 comments

Show HN: Lumina – Open-source observability for LLM applications

https://github.com/use-lumina/Lumina
4•iggycodexs•9h ago•1 comments

Show HN: I made an app that blurs my screen when I slouch

https://tomjohnell.com/posturr-a-macos-app-that-blurs-your-screen-when-you-slouch/
11•tjohnell•19h ago•2 comments

Show HN: BrowserOS – "Claude Cowork" in the browser

https://github.com/browseros-ai/BrowserOS
87•felarof•3d ago•35 comments

Show HN: Whosthere: A LAN discovery tool with a modern TUI, written in Go

https://github.com/ramonvermeulen/whosthere
273•rvermeulen98•2d ago•89 comments

Show HN: I've been using AI to analyze every supplement on the market

https://pillser.com/
91•lilouartz•3d ago•47 comments