Show HN: Wardline, a Go proxy that auto-blocks compromised AI agents Wardline, an open-source Go proxy released by developer Kabir Narang, automatically blocks compromised AI agents in real time by enforcing identity, policy, budget, and audit with statistical anomaly detection, requiring no rule writing or human intervention. The single static binary supports multiple policy backends (YAML, OPA/Rego, AWS Cedar), short-lived JWT issuance, RBAC, SCIM 2.0, and rate limiting, and is available on GitHub and GHCR for Linux, Darwin, and Windows on amd64 and arm64. Wardline is an open-source proxy that sits between your AI agents and everything they call MCP servers, tools, gRPC upstreams and enforces identity, policy, budget, and audit — with statistical anomaly detection that blocks a compromised agent in real time , no rule written for the attack and no human in the loop. One static Go binary; no database, IdP, or sidecar to start. make demo spins up a mock MCP server + Wardline and runs the scenario above The same run in the built-in read-only dashboard — the block, the anomaly that triggered it, and the policy behind it: Any caller — an AI agent, a CLI/IDE, or an app — reaches its MCP/gRPC upstreams only through Wardline, which applies identity, policy, budget, and anomaly detection in-process and writes every decision to the audit trail. Full design: Architecture https://kabirnarang39.github.io/wardline/docs/concepts/architecture/ . - Real-time anomaly auto-block Four self-baselining heuristics rate spike, novel tool, deny-rate spike, and a combined ml score z-score via Welford's algorithm — no training data, no external model that don't just alert: auto block rejects a flagged identity's calls for a bounded TTL. Enforcement, not a log line. - Three policy backends, one binary Static YAML, embedded OPA/Rego, and embedded AWS Cedar — switched by a single policy backend config key, with no external process and no network hop. - Identity & access Short-lived RS256 JWT issuance with refresh tokens and JWKS rotation, OIDC / mTLS-SPIFFE bootstrap, Kubernetes-style RBAC, SCIM 2.0 provisioning, and end-to-end tenant isolation. - Budget & rate control Two-tier per-identity and per-tenant rate limits — both must clear for a call to proceed. - Compliance & audit Structured JSON audit trail, wardline export-evidence checksummed, RSA-signable bundle for an auditor , configurable retention, and wardline infer-policy to generate a starter allow-list from observed traffic. - Federation & observability Cross-instance correlation over signed, pseudonymized anomaly summaries; OpenTelemetry tracing; a live web dashboard; and HA multi-replica deployment with shared state over Postgres. From source always works go build -o wardline ./cmd/wardline Or pull the published multi-arch image built for each tagged release docker pull ghcr.io/kabirnarang39/wardline:latest ./wardline validate-policy --file policy.yaml.example ./wardline validate-config --config wardline.yaml.example ./wardline serve --config wardline.yaml.example Point upstream at a real MCP server a proxied call 502s until you do — for a quick test, python3 -m http.server 9000 . Every request carries an X-Wardline-Identity header; policy matches on that value plus the MCP tool name: curl -X POST http://localhost:8080 \ -H "X-Wardline-Identity: agent-abc123" \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","method":"tools/call","params":{"name":"read file"}}' Prebuilt binaries linux/darwin/windows · amd64/arm64 and multi-arch images ship on every v tag via Releases https://github.com/kabirnarang39/wardline/releases and GHCR https://github.com/kabirnarang39/wardline/pkgs/container/wardline . Full docs, per-feature design notes, and honest known-limitations live on the docs site: Getting Started https://kabirnarang39.github.io/wardline/docs/getting-started/ — install, quickstart, configuration Concepts https://kabirnarang39.github.io/wardline/docs/concepts/ — architecture, policy backends, identity, audit Features https://kabirnarang39.github.io/wardline/docs/features/ — every capability in depth Deployment https://kabirnarang39.github.io/wardline/docs/deployment/ — Docker, Helm, HA, observability Framework integrations /kabirnarang39/wardline/blob/main/docs/integrations — LangChain, LlamaIndex, OpenAI Agents SDK, CrewAI, raw MCP Everything below is shipped and testable under internal/features/ /kabirnarang39/wardline/blob/main/internal/features . The v0.1 baseline proxy + policy + audit is always on; everything else is gated by a config flag. | Capability | Docs | |---|---| | Policy backends — YAML · OPA/Rego · AWS Cedar | | Anomaly detection https://kabirnarang39.github.io/wardline/docs/features/anomaly-detection/ Budget https://kabirnarang39.github.io/wardline/docs/features/budget-enforcement/ Credentials https://kabirnarang39.github.io/wardline/docs/features/credential-issuance/ SSO https://kabirnarang39.github.io/wardline/docs/features/sso/ · mTLS https://kabirnarang39.github.io/wardline/docs/features/mtls-bootstrap/ RBAC https://kabirnarang39.github.io/wardline/docs/features/rbac/ · SCIM https://kabirnarang39.github.io/wardline/docs/features/scim/ Federation https://kabirnarang39.github.io/wardline/docs/features/federation/ Compliance https://kabirnarang39.github.io/wardline/docs/features/compliance-evidence-export/ infer-policy https://kabirnarang39.github.io/wardline/docs/features/auto-generated-policy/ -packs-dir Policy packs https://kabirnarang39.github.io/wardline/docs/features/policy-pack-marketplace/ gRPC https://kabirnarang39.github.io/wardline/docs/features/grpc-transport/ HA https://kabirnarang39.github.io/wardline/docs/deployment/high-availability/ Dashboard https://kabirnarang39.github.io/wardline/docs/features/web-dashboard/ Observability https://kabirnarang39.github.io/wardline/docs/deployment/observability/ Reproducible with go test -bench , not marketing numbers. BenchmarkDecider Decide default YAML backend, Apple Silicon : ~33 ns / 0 allocations at 10 rules, ~2.4 µs at 1000 rules. The ml score false-positive claim is regression-guarded by TestDetector MLScore FalsePositiveRateOnSteadyTraffic asserts 0% false positives on steady traffic, budget < 2% . The dashboard and the X-Wardline-Identity header are unauthenticated by default — pair with credential issuance and/or rbac for real security value. Every optional capability ships off by default and fails closed. On startup Wardline logs a WARN for each insecure default still in effect, so the posture is never silent. Report vulnerabilities per SECURITY.md /kabirnarang39/wardline/blob/main/SECURITY.md . Out of the box the proxy fails closed on policy , but identity and the dashboard are open. For any real deployment, turn on: features: credential issuance: true verify a signed bearer token instead of trusting X-Wardline-Identity rbac: true gate the dashboard and admin actions on real permissions With credential issuance on, the spoofable header is replaced by RS256 bearer-token verification; with rbac on, dashboard read views and mutations require an authorized identity. Anomaly detection catches abrupt abuse but not low-and-slow ramps see its known limitations https://kabirnarang39.github.io/wardline/docs/features/anomaly-detection/ , so keep explicit policy + budget limits as the hard floor. Wardline is young and moving fast. Every feature's docs page is deliberately blunt about what it does and doesn't do. Feedback, issues, and contributions are welcome — especially on the anomaly-detection approach and threat model. See CONTRIBUTING.md /kabirnarang39/wardline/blob/main/CONTRIBUTING.md and CODE OF CONDUCT.md /kabirnarang39/wardline/blob/main/CODE OF CONDUCT.md . Architecture and engineering conventions are documented in CLAUDE.md /kabirnarang39/wardline/blob/main/CLAUDE.md ; the roadmap lives in the docs https://kabirnarang39.github.io/wardline/docs/advanced/roadmap/ .