Aegis is a self-hosted Envoy xDS control plane with built-in AI threat analysis, TLS certificate automation, and a real-time security dashboard. Run it alongside Envoy Proxy to get enterprise-grade gateway management on your home server or VPS — in one Docker container.
docker run -d \
--name aegis \
-p 8765:8765 \
-v aegis_data:/data \
axieyangb/aegis:latest
Dashboard: http://localhost:8765 · Default login: admin / aegis
| Feature | Description |
|---|---|
| Envoy xDS Gateway | Visual editor for listeners, clusters, filter chains, TLS — pushed live to Envoy via gRPC xDS |
| Traffic Analytics | Real-time request feed, top IPs, geo map, device breakdown, status code distribution |
| AI Threat Analysis | Background IP classification using Gemini / Claude / GPT / Ollama — auto-blocks high-risk IPs |
| Owl AI Assistant | Chat with your gateway — ask about traffic, threats, and config in plain language |
| TLS Cert Automation | ACME (Let's Encrypt / ZeroSSL), DNS-01 / HTTP-01 challenges, auto-renew via Envoy SDS |
| Notifications | Telegram, Discord, Slack webhooks — alert on blocks, anomalies, and daily digest |
| Geo Blocking | Country-level traffic analysis; remote or local MaxMind GeoIP lookup |
| OIDC / SSO | Optional single-sign-on via any OIDC provider (Google, Authentik, etc.) |
services:
aegis:
image: axieyangb/aegis:latest
container_name: aegis
restart: unless-stopped
ports:
- "8765:8765"
volumes:
- aegis_data:/data
environment:
- ADMIN_USERNAME=admin
- ADMIN_PASSWORD=changeme
- AUTH_ENABLED=true
envoy:
image: envoyproxy/envoy:v1.35-latest
container_name: envoy
restart: unless-stopped
depends_on: [aegis]
ports:
- "80:10080"
- "443:10443"
volumes:
- ./envoy.yaml:/etc/envoy/envoy.yaml:ro
command: [envoy, -c, /etc/envoy/envoy.yaml, --log-level, warn]
volumes:
aegis_data:
Starter envoy.yaml → github.com/axieyangb/aegis/configs
| Variable | Default | Description |
|---|---|---|
PORT | 8765 | HTTP port for the dashboard and API |
XDS_PORT | 18000 | gRPC xDS port (Envoy connects here) |
DATA_DIR | /data | Persistent data directory |
ADMIN_USERNAME | admin | Dashboard admin username |
ADMIN_PASSWORD | aegis | Dashboard admin password — change this |
AUTH_ENABLED | true | Require login to access dashboard |
BLOCK_ENABLED | true | Enable automatic IP blocking engine |
NODE_ID | home | Envoy node ID (must match node.id in envoy.yaml) |
Mount a directory or named volume to /data — Aegis stores everything here:
/data/
├── aegis.db ← SQLite database (traffic, alerts, certs, config)
└── skills/ ← Optional: override Owl AI knowledge files
└── site.md ← Custom context injected into every Owl conversation
| Port | Protocol | Purpose |
|---|---|---|
8765 | HTTP | Dashboard, REST API, WebSocket |
18000 | gRPC | Envoy xDS endpoint (ADS — listeners, clusters, secrets) |
Internet → Envoy Proxy → your services
↕ gRPC xDS (port 18000)
Aegis (port 8765)
├── xDS control plane
├── Traffic analytics (reads Envoy ALS logs)
├── AI classification engine
├── Certificate manager (ACME → Envoy SDS)
└── Dashboard + REST API
| Tag | Description |
|---|---|
latest | Latest stable release |
v1.0.0 | Specific release |
Multi-arch: linux/amd64 and linux/arm64 (Raspberry Pi, Apple Silicon NAS).
Content type
Image
Digest
sha256:b661bf37e…
Size
72.8 MB
Last updated
about 1 month ago
docker pull axieyangb/aegis