Sign inSign up

redteamsfr/llmiddler-sandbox

By redteamsfr

•Updated 7 days ago

Sandbox for LLM agent harnesses with bundled agent CLIs, transparent proxy, and analysis UI

Image
Machine learning & AI
Data science
Monitoring & observability
0

10K+

redteamsfr/llmiddler-sandbox repository overview

Description: Sandbox for LLM agent harnesses with bundled agent CLIs, transparent proxy, and analysis UI

⁠llmiddler-sandbox — sandbox for analyzing and debugging LLM agent harnesses

A ready-to-use Linux environment to run, instrument, and analyze LLM agents from the CLI.

Outbound traffic from every embedded tool is automatically routed through LLMiddler, so you can observe, replay, or modify the requests without changing a line of your harness code.

⁠Quick start

Create a .env file:

MISTRAL_API_KEY=...

Start the container:

docker run --init \
  -p 8090:8090 -p 9090:9090 -p 9091:9091 \
  --env-file .env \
  -e TZ=Europe/Paris \
  -it --rm \
  redteamsfr/llmiddler-sandbox:latest-light bash

Then open, from the host:

The proxy UI listens in plain HTTP with a trivial default token. If you expose it, prefer binding it to loopback only: -p 127.0.0.1:9091:9091.

⁠Working on your own code

The /workspace/mount directory is meant to be bind-mounted from the host:

docker run --init \
  -p 8090:8090 -p 9090:9090 -p 9091:9091 \
  --env-file .env \
  -v "$PWD:/workspace/mount" \
  -it --rm \
  redteamsfr/llmiddler-sandbox:latest-light bash

Your current host directory shows up under /workspace/mount inside the container, editable from either the in-container shell or your local IDE. Add :ro for a read-only mount.

⁠Ports

PortServicePurpose
8090llmiddler-gatewayAnalysis Web UI (/_ui/) + /_ingest capture endpoint
9090llmiddler-proxyTransparent HTTP/HTTPS MITM proxy + CA cert (/ca.crt)
9091llmiddler-proxyReal-time proxy Web UI: live clients + TLS fingerprints
8233TemporalLocal Temporal server UI (internal orchestration; optional)

⁠Configuration file paths

The gateway and the proxy each read a YAML config file. The locations are overridable via environment variables — the defaults preserve the built-in behavior, so you only set these if you bind-mount your own config:

VariableDefaultComponent
LLMIDDLER_CONFIG/opt/llmiddler/config.yamlllmiddler-gateway
LLMIDDLER_PROXY_CONFIG/opt/llmiddler-proxy/llmiddler-proxy.yamlllmiddler-proxy

For example, to run the proxy with your own config file:

docker run --init \
  -p 8090:8090 -p 9090:9090 -p 9091:9091 \
  --env-file .env \
  -e LLMIDDLER_PROXY_CONFIG=/workspace/mount/my-proxy.yaml \
  -v "$PWD:/workspace/mount" \
  -it --rm \
  redteamsfr/llmiddler-sandbox:latest-light bash

⁠What's inside

Agents and CLIs

  • vibe — Mistral AI CLI
  • opencode
  • claude — Anthropic CLI
  • confluence-reader / confluence-writer — read from and publish to Confluence
  • temporal — Temporal CLI

LLM observability

  • llmiddler-proxy — transparent HTTPS proxy on port 9090 with a freshly-generated CA installed in the system trust store (served at http://localhost:9090/ca.crt): no TLS plumbing required on the client side. Its own real-time web UI runs on port 9091 (http://localhost:9091/?t=secret) and shows live intercepted clients and their TLS fingerprints.
  • llmiddler-gateway — ingest service and analysis UI on port 8090 (http://localhost:8090/_ui/).
  • HTTP_PROXY / HTTPS_PROXY / SSL_CERT_FILE / REQUESTS_CA_BUNDLE / NODE_EXTRA_CA_CERTS pre-configured for Python, Go, and Node.js.

⁠How it works

  1. Configure your harness to use a standard LLM endpoint (Mistral, OpenAI, Anthropic, etc.).
  2. The embedded transparent proxy intercepts the outbound request, forwards it to the provider, and ships a copy to the gateway for analysis.
  3. The Web UI shows you conversations, token usage, and tool calls.

No harness changes needed: as long as it honors the HTTP_PROXY / HTTPS_PROXY environment variables (which most SDKs do), it just works.

⁠Image variants

TagContents
:latest-lightCLIs + proxy + gateway, no browser
:latest+ Chromium, Camofox, Lightpanda, Playwright

The light variant covers text-only workflows. The full image adds browsers for agents that can navigate the web.

⁠Tags and versioning policy

Two flavors of tags are published, with different stability guarantees.

Pinned tags — :vX.Y.Z-light, :vX.Y.Z

Each git tag of the form vX.Y.Z triggers a build that pushes the matching Docker tag. Treat these as immutable: once published, a given vX.Y.Z[-light] tag is meant to keep referencing the same image. We do not re-publish over an existing version tag.

If you want a reproducible deployment, pin to vX.Y.Z[-light] (or to the image digest, @sha256:..., for a stronger guarantee that survives even accidental overwrites).

Floating tags — :latest-light, :latest

These are updated on every release and always point to the most recent vX.Y.Z[-light] build. Convenient for trying things out, but not recommended for any environment where you care about reproducibility.

The image follows semantic versioning⁠: a bump in MAJOR may include breaking changes, MINOR adds features in a backwards-compatible way, PATCH is bug fixes only.


Enjoy.

⁠Demo License

This Docker image is provided free of charge for evaluation and demonstration purposes only.

⁠Permitted Use

You may:

  • Download and run this image for personal or business evaluation.
  • Test the application's features.
  • Use it for demonstrations, proofs of concept, and internal testing.

⁠Restrictions

You may not:

  • Modify, copy, adapt, create derivative works from, reverse engineer, decompile, or disassemble the software, except to the extent expressly permitted by applicable law.
  • Redistribute, sublicense, sell, rent, lease, publish, or commercially exploit this Docker image or any software component included within it without prior written authorization from the copyright holder.
  • Remove, alter, or obscure any copyright, trademark, license, or proprietary notices contained in the software or Docker image.
  • Use this Docker image for production workloads, commercial deployments, or customer-facing services without obtaining an appropriate commercial license.

⁠Intellectual Property

The software, Docker image, and all associated intellectual property remain the exclusive property of the copyright holder. This license does not transfer ownership of any intellectual property rights.

⁠No Warranty

This software is provided "AS IS", without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement.

⁠Limitation of Liability

In no event shall the copyright holder be liable for any claim, damages, or other liability arising from or relating to the use of this software.

⁠Commercial License

A commercial license is required for production use or any commercial deployment beyond evaluation. Please contact the author for licensing information.

© 2026 redteamsfr. All rights reserved.

Tag summary

Content type

Image

Digest

sha256:ab7351205…

Size

417.2 MB

Last updated

7 days ago

docker pull redteamsfr/llmiddler-sandbox:latest-light