Skip to content

feat: add optional pentest sandbox setup (egress-firewalled Docker overlay) - #121

Draft
niklashaug wants to merge 2 commits into
peerigon:mainfrom
niklashaug:feat/pentest-sandbox
Draft

niklashaug wants to merge 2 commits into
peerigon:mainfrom
niklashaug:feat/pentest-sandbox

Conversation

@niklashaug

Copy link
Copy Markdown
Member

Summary

  • Adds an optional docker-compose overlay + firewall sidecar that blocks real internet egress from the app under test, so a dynamic AI pentest (e.g. Strix) or anything else run against it can't accidentally hit real third-party services (email/push/payment providers, ...).
  • Ships as generic building blocks (docker/apply-firewall.sh, docker/Dockerfile.firewall) plus a parameterized skeleton/scripts (docker-compose.pentest.yml, scripts/run-pentest.sh, scripts/verify-pentest-network-isolation.sh) that a new project's AI-assisted customize flow fills in from its own docker-compose.yml - same pattern already used for package.json/README/LICENSE customization.
  • The included gate script proves isolation actually holds (live egress check against the real app container) before ever starting a pentest tool, rather than just trusting an instruction/prompt.
  • Piloted end-to-end on konsens: see peerigon/IT#335 for the background and process this is part of, and the linked comment for pilot results.

Test plan

  • Review the new README section for clarity (fits the existing "Customize Template Project Files" flow)
  • Try the customize-and-run flow on a project with a docker-compose.yml, confirm ./scripts/run-pentest.sh brings up the sandbox, verifies isolation, and only then starts Strix
  • Confirm the stack tears down cleanly on both success and failure

🤖 Generated with Claude Code

niklashaug and others added 2 commits September 23, 2026 15:48
…erlay)

Adds a docker-compose overlay plus a network-namespace-sharing firewall
sidecar that blocks real internet egress from the app under test, so a
dynamic AI pentest (e.g. Strix) or anything else run against it can't
accidentally hit real third-party services. Piloted on konsens, see
peerigon/IT#335 for background.

Ships as generic building blocks (docker/apply-firewall.sh,
Dockerfile.firewall) plus a parameterized skeleton/scripts that a new
project's AI-assisted customize flow fills in from its own
docker-compose.yml, following the same pattern already used for
package.json/README/LICENSE customization.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Format README.md and network-isolation-check.mjs with oxfmt.
- Add a Node-globals eslint override scoped to scripts/**/*.mjs (it's a
  standalone CLI script, not app code) and allow process.exit() there.
- Rewrite the reachability probe to run in parallel (Promise.all instead
  of await-in-loop), use function declarations, and stringify numbers in
  template literals per the repo's lint rules.
- Type-narrow the caught error safely instead of relying on implicit any.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

currently thinking if the /scripts directory is a good place for all of this because this will be inline in future projects, maybe this should be nested inside of some .template folder or something so it's clear that those scripts come from the template and a project can have its own /scripts directory if it wants to

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant