Mesh is an authoritative, deterministic security control plane that sits between developer commands.
73
A small, fast, secure-by-default developer security control plane over Docker.
Complex infrastructure underneath. Simple commands above.
Mesh is an authoritative, deterministic security control plane that sits between developer commands and the Docker execution layer.
Instead of requiring users to manually install toolchains, compilers, or build from source, Mesh is distributed as a lightweight, cross-platform Docker container image: ethernmyth/mesh:latest. Any developer or CI/CD pipeline with Docker installed can pull the image and immediately enforce preflight security policies, manage encrypted credentials, analyze stack topologies, run diagnostics, and automate container hardening without platform-specific dependencies.
Modern development teams rely heavily on Docker and Docker Compose to rapidly spin up local microservices, databases, caches, and web applications. However, local developer configurations frequently suffer from severe security misconfigurations:
0.0.0.0 or bound to public interfaces, exposing internal data stores to the host network, LAN, or public internet.docker-compose.yml, embedded in .env files, logged to stdout/stderr, or pushed to Git repositories.root (UID 0), execute in privileged: true mode, or mount /var/run/docker.sock, giving compromised containers root escape capabilities on the host.Mesh solves this by providing a unified, deterministic preflight security control plane:
0600 permissions) and are securely wiped upon mesh down.mesh lockdown --apply) transforms insecure compose definitions into hardened, least-privilege configurations with automatic backups.mesh.yaml (User Config)
│
▼
Config ──► Policy Engine ──► Deterministic Security Checks ──► Runtime (Docker Engine)
│ │
│ ├──► Graph / Doctor / Security Score / Lockdown
│
└──► Secrets Vault
│
├──► Encrypted local vault (AES-256-GCM / PBKDF2)
│
└──► Transient runtime injection (Scrubbed on down)
Optional (User-configured local LLM):
Diagnostic context ──► Secret Redaction ──► Local Ollama ──► Advisory Notice (Human-in-the-loop)
Important
**Mesh never hardcodes any ports, container names, service topologies, images, or AI backends.** All infrastructure parameters are fully supplied and customized by the user in `mesh.yaml`.
| Component | User Configuration Freedom | Deterministic Mesh Behavior |
|---|---|---|
| Database (PostgreSQL, MySQL, Redis, Mongo, etc.) | User chooses service name (postgres, db, auth-store), image (postgres:18-alpine, mysql:8.4, mariadb:11, redis:7-alpine), and port bindings (e.g. "127.0.0.1:5433:5432", "127.0.0.1:5432:5432", or internal bridge only). | Evaluates database port bindings dynamically. If any database port is exposed publicly (e.g. without 127.0.0.1: loopback), Mesh flags or blocks it according to configured policy—regardless of what port number is used. |
| Web & API (Nginx, Caddy, Go, Node, Python, etc.) | User chooses any container image, application name, and port mapping (e.g. "8080:80", "3000:3000", "8443:443", "5000:5000"). | Analyzes privileges, healthchecks, resource limits, and network isolation for the user's specific services without assuming standard ports. |
| Secrets & Credentials | User creates and names arbitrary secrets (e.g. pg_password, jwt_secret, stripe_api_key, oauth_token). | Encrypts secrets in AES-256-GCM vault, injects them into transient runtime files dynamically, and sanitizes all secret files on mesh down. |
| Advisory AI | User specifies the provider (ollama, noop), endpoint URL (e.g. http://localhost:11434, http://host.docker.internal:11434, http://192.168.1.50:11434), and model name (e.g. qwen3, llama3.2, mistral, deepseek-r1). | Completely disabled by default (enabled: false). When enabled, connects only to the user-specified endpoint, strips all secrets before sending, and provides human-readable advice. |
ethernmyth/mesh:latest)Because Mesh runs as a Docker container, you do not need to install Go, compilers, or build tools on your machine. Simply pull the image from Docker Hub and start using Mesh immediately.
docker pull ethernmyth/mesh:latest
Run Mesh by mounting the Docker socket and your current working directory:
# General syntax
docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-v "$PWD:/work" \
-w /work \
-e MESH_VAULT_PASSWORD \
ethernmyth/mesh:latest <command>
To run mesh seamlessly as a native command, add an alias or function to your shell profile:
Add this line to ~/.bashrc or ~/.zshrc:
alias mesh='docker run --rm -it -v /var/run/docker.sock:/var/run/docker.sock -v "$PWD:/work" -w /work -e MESH_VAULT_PASSWORD ethernmyth/mesh:latest'
Then reload your shell:
source ~/.bashrc # or source ~/.zshrc
Add this function to your PowerShell profile ($PROFILE):
function mesh {
docker run --rm -it `
-v /var/run/docker.sock:/var/run/docker.sock `
-v "${PWD}:/work" `
-w /work `
-e MESH_VAULT_PASSWORD `
ethernmyth/mesh:latest $args
}
Now you can simply type mesh init, mesh security scan, mesh up, etc., in any project directory!
All commands are available directly through the Docker image:
| Command | Description |
|---|---|
mesh init | Initialize a new mesh.yaml configuration with secure defaults |
mesh up [-d] [services...] | Run preflight policy checks and start stack containers via Docker Compose |
mesh down | Stop container stack and securely wipe transient runtime secrets |
mesh status | Inspect real-time container states, health checks, and exposed ports |
mesh logs [-f] <service> | Stream logs for a specific service |
mesh graph | Render ASCII dependency and topology tree |
mesh doctor | Run comprehensive environment, Docker engine, configuration, and security diagnostics |
mesh security scan [--fail-closed] | Run deterministic preflight security checks against configured policies |
mesh security score | Calculate 0–100 security score with category deductions and grading |
mesh security secrets | Scan configuration and environment for secret references and hardcoded credentials |
mesh secret create <name> | Generate cryptographically secure random secret and store in encrypted vault |
mesh secret list | List secrets metadata (names, versions, timestamps; values never displayed) |
mesh secret rotate <name> | Rotate secret with a new cryptographically secure encrypted random value |
mesh lockdown --preview | Preview proposed automated hardening modifications without altering files |
mesh lockdown --apply [-y] | Apply automated hardening transformations to mesh.yaml with automatic .bak backup |
mesh ai explain | Generate advisory architecture and boundary analysis (Local LLM) |
mesh ai diagnose | Generate advisory diagnostic analysis for stack findings (Local LLM) |
mesh ai security | Generate advisory hardening recommendations prioritized by security score (Local LLM) |
Follow these steps to run the complete Mesh workflow using the Docker image.
In your project directory, initialize a new mesh.yaml:
mesh init
This generates a starter mesh.yaml file in your workspace.
Edit mesh.yaml with your custom services, images, ports, and policy rules. Note how all ports and images are user-defined:
name: my-app-stack
services:
# User-configured frontend / reverse proxy
gateway:
image: nginx:alpine
user: "10001:10001"
read_only: true
ports:
- "8080:80" # User-specified port mapping
resources:
limits:
cpu: "0.5"
memory: "256M"
healthcheck:
test: ["CMD-SHELL", "wget -q --spider http://localhost:80 || exit 1"]
# User-configured backend API
api:
image: my-company/backend-api:v1.2.0
user: "10001:10001"
read_only: true
ports:
- "3000:3000" # User-specified port mapping
secrets:
- app_secret_key
- db_password
depends_on:
- postgres
resources:
limits:
cpu: "1.0"
memory: "512M"
healthcheck:
test: ["CMD-SHELL", "wget -q --spider http://localhost:3000/health || exit 1"]
# User-configured PostgreSQL database
postgres:
image: postgres:18-alpine # User-specified database image
user: "10001:10001"
read_only: true
ports:
- "127.0.0.1:5433:5432" # Custom user-defined host port (5433) safely bound to localhost
secrets:
- db_password
resources:
limits:
cpu: "1.0"
memory: "1G"
healthcheck:
test: ["CMD-SHELL", "pg_isready || exit 1"]
security:
public_database: deny
security:
privileged: deny
host_network: deny
docker_socket: deny
root_user: warn
public_database: deny
writable_root_filesystem: warn
missing_healthcheck: warn
resource_limits: require
excessive_capabilities: deny
hardcoded_secrets: deny
# User-configured local AI (Disabled by default)
ai:
enabled: false
provider: ollama
endpoint: http://host.docker.internal:11434 # User-defined local endpoint
model: qwen3 # User-defined model
Audit your stack configuration deterministically before running containers:
# Run deterministic policy scan
mesh security scan
# View quantitative security score and category deductions (A-F grade)
mesh security score
If any service violates a deny or require rule (such as public database port exposure, privileged mode, or missing resource limits), mesh security scan --fail-closed immediately halts execution with a non-zero exit code.
Manage credentials without ever writing plaintext passwords into YAML files, Dockerfiles, or Git:
# Optional: supply vault master passphrase (or omit to use local protected vault.key)
export MESH_VAULT_PASSWORD="my-secure-master-passphrase"
# Generate cryptographically secure random secrets
mesh secret create db_password
mesh secret create app_secret_key
# List secrets in the vault (metadata only; values are NEVER displayed)
mesh secret list
# Verify secret hygiene and audit bindings
mesh security secrets
# Rotate a secret safely
mesh secret rotate db_password
Inspect service dependencies and verify environment health:
# Display dependency topology tree
mesh graph
# Run comprehensive environment diagnostics
mesh doctor
Let Mesh automatically remediate configuration weaknesses (non-root enforcement, read-only rootfs, localhost port restrictions, resource limits, healthchecks):
# Preview proposed hardening changes without altering files
mesh lockdown --preview
# Apply hardening transformations to mesh.yaml (creates automatic .bak backup)
mesh lockdown --apply -y
# Re-run security scan and score to confirm compliance
mesh security scan
mesh security score
Start the stack with preflight validation and automated transient runtime secret injection:
# Launch containers in detached mode
mesh up -d
# Inspect live container states, health status, and port bindings
mesh status
# Stream service logs
mesh logs api
# Run doctor diagnostics against the live running stack
mesh doctor
When you enable AI in mesh.yaml with your preferred local Ollama endpoint and model:
# Architectural explanation and boundary analysis
mesh ai explain
# Finding diagnostics and remediation guidance
mesh ai diagnose
# Quantitative hardening advice prioritized by security score
mesh ai security
Note
All diagnostic context is automatically sanitized through Mesh's secret redactor before being sent to the local LLM. The AI operates in advisory mode only and cannot modify configurations or execute commands.
When stopping your containers, Mesh automatically scrubs all transient secret files from disk:
mesh down
Policies in mesh.yaml support four deterministic actions:
deny: Blocks container launch (mesh up fails closed with a non-zero exit).require: Mandatory security parameter; blocks startup if omitted.warn: Emits an advisory finding in CLI output but permits execution.allow: Silently permits the configuration option.You can set global policies under the top-level security: block, and override specific rules per service under services.<name>.security:.
The Mesh implementation strictly adheres to these non-negotiable security guarantees:
MESH_VAULT_PASSWORD.deny or require policy violations immediately block container startup (mesh up)./var/run/docker.sock mounts into containers as critical security risks.mesh down.If you are developing or contributing to Mesh, you can build the Docker image locally:
# Run unit and integration tests
go test -v ./...
go vet ./...
# Build the official lightweight scratch container image
docker build -t ethernmyth/mesh:latest .
Container properties:
scratch (zero overhead, no shell, no package manager, no compiler)65534:65534 (rootless nobody)CGO_ENABLED=0) with stripped symbols (-ldflags="-s -w")docker.sock is mounted into application containers and interacts with Docker through least-privilege operations.MESH_VAULT_PASSWORD is supplied, keys are derived via PBKDF2 (100,000 iterations). Plaintext secrets are decrypted in-memory only during runtime injection and written to transient files with 0600 permissions.mesh lockdown --apply).Created and Maintained by: Ethern Myth
Content type
Image
Digest
sha256:e7c57564d…
Size
2.9 MB
Last updated
28 days ago
docker pull ethernmyth/mesh