-
-
Notifications
You must be signed in to change notification settings - Fork 5
Home
A self-hosted secure web gateway: forward proxy, WAF inspection over ICAP, and DNS sinkholing in one stack of five containers, with a web UI in front.
This wiki is the operational companion to the documentation site. The docs are the reference: introduction, getting started, configuration, architecture, blacklists, security and the API. The wiki carries what you need once it is running, and what is currently known to be broken.
- Known issues: what is open, what changes how you operate the stack, and what was fixed in a release you may not have taken yet
- Ports and networking: what listens where, which ports are host-bound, why the proxy refuses some clients, and the port conflict that stops a first install
- Day-two operations: updating, backup and restore, health checks, and the end-to-end suite
- Driving it from an agent: the bundled MCP server, its tools, and which of them change live proxy behaviour
- Documentation site: getting started, configuration, architecture, security
- DEPLOYMENT.md: deployment, reverse proxy and TLS
- BENCHMARKS.md and the CHANGELOG
- Security advisories: upstream Squid CVEs and how this image handles them
The backend refuses to start on a weak password or a known secret. An empty, common, or shorter-than-8-character BASIC_AUTH_PASSWORD and a recognisable SECRET_KEY are rejected deliberately. A backend that will not boot is usually this, not a bug.
HTTPS is not inspected until you enable SSL bump and install the generated CA on your clients. Until then, HTTPS is filtered by host, IP and DNS only, and no WAF body rule ever sees it.
The proxy accepts only RFC1918 and localhost sources by default. If clients are not being filtered, check the source address before anything else.
Secure Proxy Manager · README · Documentation · Report a bug · Report a vulnerability privately