# agent-firewall

Network isolation tool for monitoring and restricting HTTP/HTTPS requests

## Usage [#usage]

```console
coder agent-firewall [flags] [args...]
```

## Description [#description]

```console
boundary creates an isolated network environment for target processes, intercepting HTTP/HTTPS traffic through a transparent proxy that enforces user-defined allow rules.
```

## Options [#options]

### --config [#--config]

|             |                                |
| ----------- | ------------------------------ |
| Type        | <code>yaml-config-path</code>  |
| Environment | <code>$BOUNDARY\_CONFIG</code> |

Path to YAML config file.

### --allow [#--allow]

|             |                               |
| ----------- | ----------------------------- |
| Type        | <code>string</code>           |
| Environment | <code>$BOUNDARY\_ALLOW</code> |

Allow rule (repeatable). These are merged with allowlist from config file. Format: "pattern" or "METHOD\[,METHOD] pattern".

### --log-level [#--log-level]

|             |                                    |
| ----------- | ---------------------------------- |
| Type        | <code>string</code>                |
| Environment | <code>$BOUNDARY\_LOG\_LEVEL</code> |
| YAML        | <code>log\_level</code>            |
| Default     | <code>warn</code>                  |

Set log level (error, warn, info, debug).

### --log-dir [#--log-dir]

|             |                                  |
| ----------- | -------------------------------- |
| Type        | <code>string</code>              |
| Environment | <code>$BOUNDARY\_LOG\_DIR</code> |
| YAML        | <code>log\_dir</code>            |

Set a directory to write logs to rather than stderr.

### --proxy-port [#--proxy-port]

|             |                           |
| ----------- | ------------------------- |
| Type        | <code>int</code>          |
| Environment | <code>$PROXY\_PORT</code> |
| YAML        | <code>proxy\_port</code>  |
| Default     | <code>8080</code>         |

Set a port for HTTP proxy.

### --pprof [#--pprof]

|             |                               |
| ----------- | ----------------------------- |
| Type        | <code>bool</code>             |
| Environment | <code>$BOUNDARY\_PPROF</code> |
| YAML        | <code>pprof\_enabled</code>   |

Enable pprof profiling server.

### --pprof-port [#--pprof-port]

|             |                                     |
| ----------- | ----------------------------------- |
| Type        | <code>int</code>                    |
| Environment | <code>$BOUNDARY\_PPROF\_PORT</code> |
| YAML        | <code>pprof\_port</code>            |
| Default     | <code>6060</code>                   |

Set port for pprof profiling server.

### --jail-type [#--jail-type]

|             |                                    |
| ----------- | ---------------------------------- |
| Type        | <code>string</code>                |
| Environment | <code>$BOUNDARY\_JAIL\_TYPE</code> |
| YAML        | <code>jail\_type</code>            |
| Default     | <code>nsjail</code>                |

Jail type to use for network isolation. Options: nsjail (default), landjail.

### --use-real-dns [#--use-real-dns]

|             |                                        |
| ----------- | -------------------------------------- |
| Type        | <code>bool</code>                      |
| Environment | <code>$BOUNDARY\_USE\_REAL\_DNS</code> |
| YAML        | <code>use\_real\_dns</code>            |

Use real DNS in the jail instead of the dummy DNS (allows DNS exfiltration). Default: false.

### --no-user-namespace [#--no-user-namespace]

|             |                                             |
| ----------- | ------------------------------------------- |
| Type        | <code>bool</code>                           |
| Environment | <code>$BOUNDARY\_NO\_USER\_NAMESPACE</code> |
| YAML        | <code>no\_user\_namespace</code>            |

Do not create a user namespace. Use in restricted environments that disallow user NS (e.g. Bottlerocket in EKS auto-mode).

### --disable-audit-logs [#--disable-audit-logs]

|             |                                    |
| ----------- | ---------------------------------- |
| Type        | <code>bool</code>                  |
| Environment | <code>$DISABLE\_AUDIT\_LOGS</code> |
| YAML        | <code>disable\_audit\_logs</code>  |

Disable sending of audit logs to the workspace agent when set to true.

### --log-proxy-socket-path [#--log-proxy-socket-path]

|             |                                                                |
| ----------- | -------------------------------------------------------------- |
| Type        | <code>string</code>                                            |
| Environment | <code>$CODER\_AGENT\_BOUNDARY\_LOG\_PROXY\_SOCKET\_PATH</code> |
| Default     | <code>/tmp/boundary-audit.sock</code>                          |

Path to the socket where the boundary log proxy server listens for audit logs.

### --version [#--version]

|      |                   |
| ---- | ----------------- |
| Type | <code>bool</code> |

Print version information and exit.

### --enable-session-correlation [#--enable-session-correlation]

|             |                                                       |
| ----------- | ----------------------------------------------------- |
| Type        | <code>bool</code>                                     |
| Environment | <code>$BOUNDARY\_SESSION\_CORRELATION\_ENABLED</code> |
| YAML        | <code>session\_correlation\_enabled</code>            |

Enable session correlation header injection. When no inject targets are configured, the target is auto-derived from CODER\_AGENT\_URL (set automatically inside Coder workspaces). Disable for deployments without Coder AI Gateway in front.

### --session-id-inject-target [#--session-id-inject-target]

|             |                                                     |
| ----------- | --------------------------------------------------- |
| Type        | <code>string</code>                                 |
| Environment | <code>$BOUNDARY\_SESSION\_ID\_INJECT\_TARGET</code> |

Inject target for session correlation headers. Repeat the flag once per target; each value describes exactly one target. Format: "domain=<host> \[path=<glob>]". Example: --session-id-inject-target "domain=prod.coder.com path=/api/v2/aibridge/\*".
