No description
  • TypeScript 70.4%
  • JavaScript 23%
  • Shell 3.9%
  • Python 0.9%
  • Go 0.7%
  • Other 1.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-05 15:40:03 -07:00
.claude/skills feat: combine all build-test workflows into single build-test.md (#1157) 2026-03-10 17:44:57 -07:00
.github Add regression test for AWF_HOST_PATH recovery across the sudo secure_path boundary (#8173) 2026-09-05 17:54:18 +00:00
.husky ci: add conventional commits and improve release process (#49) 2025-11-25 11:05:12 -08:00
.specify feat(cli): add --agent-timeout flag for execution time limit (#1242) 2026-03-12 14:02:23 -07:00
benchmarks feat: add historical benchmark storage and trend reporting (#1874) 2026-04-09 16:52:40 -07:00
containers Upgrade gh-aw to latest pre-release (#8166) 2026-09-05 10:35:20 -07:00
docs Define dynamic repository enclave contract (#8196) 2026-09-05 12:38:23 -07:00
docs-site Preinstall Chromium runtime libraries in the agent image (#8022) 2026-09-02 17:20:30 -07:00
eslint-rules chore(deps-dev): bump eslint from 8.57.1 to 10.0.0 in the linting group (#581) 2026-02-10 13:07:51 -08:00
examples refactor(copilot): drop COPILOT_API_KEY, broaden BYOK trigger (#4235) 2026-06-03 11:39:37 -07:00
guest feat: bind Cloud Hypervisor artifacts to attested release manifests (#7891) 2026-08-31 10:00:18 -07:00
paper-data chore: upgrade gh-aw to v0.69.3 and recompile all workflows (#2170) 2026-04-23 10:35:11 -07:00
samples/audit Shrink Squid negative DNS TTL to stop caching transient SERVFAILs (#8171) 2026-09-05 10:52:49 -07:00
schemas docs: sync schemas and specs with source changes (#7789) 2026-08-27 12:21:44 -07:00
scripts docs: add runner doctor A24 for read-only ARC/DinD credential overlays (#8114) 2026-09-04 16:33:46 -07:00
src Enable host-gateway setup for explicit Ollama host domains (#8172) 2026-09-05 15:40:03 -07:00
tests Add regression test for AWF_HOST_PATH recovery across the sudo secure_path boundary (#8173) 2026-09-05 17:54:18 +00:00
.dockerignore first commit 2025-10-22 02:32:54 +00:00
.gitattributes chore: upgrade gh-aw to v0.86.0 pre-release and recompile workflows (#7027) 2026-08-07 07:45:33 -07:00
.gitignore Remove Firecracker support (#7362) 2026-08-14 14:06:53 -07:00
.grant.yaml ci: add required supply-chain scan on every PR (#6530) 2026-07-23 11:05:10 -07:00
.grype.yaml chore: upgrade gh-aw workflows to v0.88.4 (#8093) 2026-09-04 09:49:57 -07:00
.markdownlint.json fix: update vulnerable dependencies (flatted, markdownlint-cli2) (#1374) 2026-03-19 16:07:38 -07:00
.npmrc chore: update safe npm dependencies (#7983) 2026-09-01 16:40:04 -07:00
action.yml feat: add enclave agent executor (#6990) 2026-08-07 10:02:19 -07:00
AGENTS.md docs: update architecture docs with three-component overview (#1340) 2026-03-17 13:59:23 -07:00
babel.config.js feat: configure jest for esm dependency compatibility (#430) 2026-02-04 12:14:32 -08:00
CLAUDE.md chore: remove bounded-query terminology (#7735) 2026-08-25 14:36:32 -07:00
CODE_OF_CONDUCT.md first commit 2025-10-22 02:32:54 +00:00
commitlint.config.js feat: run agent container processes as non-root user (#90) 2025-12-04 14:44:44 -08:00
CONTRIBUTING.md Restore --ignore-scripts for engine CLI installs in lock files, add regression guard, install Claude native binary explicitly, and harden Smoke Codex safe-output targeting (#2840) 2026-05-10 10:48:12 -07:00
COVERAGE_SUMMARY.md Add test coverage infrastructure with logger tests and comprehensive documentation (#23) 2025-10-30 12:08:46 -07:00
eslint.config.mjs chore(deps-dev): bump eslint from 8.57.1 to 10.0.0 in the linting group (#581) 2026-02-10 13:07:51 -08:00
install.sh [Deps] Safe patch/minor devDependency refresh (2026-04-17) + Node minimum alignment (#2075) 2026-04-18 12:43:54 -07:00
jest.config.js feat: add unit tests for benchmark statistics and threshold logic (#1766) 2026-04-07 16:59:31 -07:00
LICENSE first commit 2025-10-22 02:32:54 +00:00
package-lock.json chore: update safe npm dependencies (#7983) 2026-09-01 16:40:04 -07:00
package.json chore: update safe npm dependencies (#7983) 2026-09-01 16:40:04 -07:00
README.md docs(auth): list Google Vertex AI as a supported API-proxy target in README (#7957) 2026-09-01 07:03:50 -07:00
skill.md refactor: remove --enable-chroot flag, make chroot mode always-on (#714) 2026-02-12 14:01:59 -08:00
test-chroot.sh refactor: remove --enable-chroot flag, make chroot mode always-on (#714) 2026-02-12 14:01:59 -08:00
test-copilot-sandbox.ts Add volume mount parsing and configuration to CLI and Docker manager (#46) 2025-11-24 12:28:14 -08:00
test-token-unset.sh fix: unset sensitive tokens from entrypoint environ after agent starts (#809) 2026-02-12 23:49:43 -08:00
TESTING.md feat: configure jest for esm dependency compatibility (#430) 2026-02-04 12:14:32 -08:00
tsconfig.check.json feat(ci): add TypeScript type checking to CI (#303) 2026-01-17 12:55:37 -08:00
tsconfig.json refactor: deduplicate logs-stats/logs-summary pipeline and test scaffolding (#2433) 2026-05-03 16:32:39 -07:00

Agentic Workflow Firewall

Warning

Releases v0.25.21 through v0.25.39 were retired due to a bug that impacted billing. If you are running one of these versions, please upgrade to the latest release as soon as possible.

A network firewall for agentic workflows that restricts outbound HTTP/HTTPS to an allowlist of domains.

Tip

This project is a part of GitHub's explorations of Agentic Workflows. For more background, check out the project page!

How it works

awf runs your command inside a Docker sandbox with three containers:

  • Squid proxy — filters outbound traffic by domain allowlist
  • Agent — runs your command; all HTTP/HTTPS is routed through Squid
  • API proxy sidecar (optional) — holds LLM API keys so they never reach the agent process

Requirements

  • Docker: 20.10+ with Docker Compose v2
  • Node.js: 20.19.0+ (for building from source)
  • OS: Ubuntu 22.04+ or compatible Linux distribution (x86_64 and arm64)

See Compatibility for full details on supported versions and tested configurations.

Get started fast

curl -sSL https://raw.githubusercontent.com/github/gh-aw-firewall/main/install.sh | sudo bash
sudo awf --allow-domains github.com -- curl https://api.github.com

The -- separator divides firewall options from the command to run.

To inspect the API proxy endpoints and models without running an agent command, use awf --reflect. It prints the /reflect JSON response to stdout.

Feature highlights

  • Declarative config support: --config <path> with JSON/YAML + published JSON Schema
  • Domain and URL controls: allow/deny domain rules, SSL Bump (--ssl-bump), and URL patterns (--allow-urls, requires --ssl-bump)
  • Data protection controls: DLP scanning (--enable-dlp), DNS-over-HTTPS, and agent runtime limits (--agent-timeout)
  • API proxy capabilities: OpenAI, Anthropic, Copilot, Gemini, and Google Vertex AI targets with rate limits, token steering, and Anthropic auto-cache
  • Infrastructure flexibility: upstream proxy chaining, host service access, Docker-in-Docker, custom mounts, memory limits, and TTY mode
  • Operational tooling: pre-download images and inspect logs/stats/summaries/audits from live or saved runs

CLI subcommands

  • awf predownload — pre-pull runtime images for faster startup or offline environments
  • awf logs — inspect firewall logs in raw/pretty/json
    • awf logs stats — aggregate traffic statistics
    • awf logs summary — markdown/json summaries (great for GitHub Actions step summaries)
    • awf logs audit — audit view with policy-rule matching (requires policy-manifest.json, typically from --audit-dir)

For the complete CLI surface area, run awf --help.

GitHub Action quick start

steps:
  - uses: actions/checkout@v4
  - name: Setup AWF
    uses: github/gh-aw-firewall@v1
  - name: Run command through firewall
    run: sudo awf --allow-domains github.com,api.github.com -- curl https://api.github.com

See GitHub Actions for advanced setup and awf logs summary examples.

Explore the docs

Development

  • Install dependencies: npm install
  • Run tests: npm test
  • Build: npm run build

Contributing

Contributions welcome! Please see CONTRIBUTING.md for guidelines.

License

MIT