Sandbox for LLM agent harnesses with bundled agent CLIs, transparent proxy, and analysis UI
10K+
Description: Sandbox for LLM agent harnesses with bundled agent CLIs, transparent proxy, and analysis UI
A ready-to-use Linux environment to run, instrument, and analyze LLM agents from the CLI.
Outbound traffic from every embedded tool is automatically routed through LLMiddler, so you can observe, replay, or modify the requests without changing a line of your harness code.
Create a .env file:
MISTRAL_API_KEY=...
Start the container:
docker run --init \
-p 8090:8090 -p 9090:9090 -p 9091:9091 \
--env-file .env \
-e TZ=Europe/Paris \
-it --rm \
redteamsfr/llmiddler-sandbox:latest-light bash
Then open, from the host:
secret).The proxy UI listens in plain HTTP with a trivial default token. If you expose it, prefer binding it to loopback only:
-p 127.0.0.1:9091:9091.
The /workspace/mount directory is meant to be bind-mounted from the host:
docker run --init \
-p 8090:8090 -p 9090:9090 -p 9091:9091 \
--env-file .env \
-v "$PWD:/workspace/mount" \
-it --rm \
redteamsfr/llmiddler-sandbox:latest-light bash
Your current host directory shows up under /workspace/mount inside the container, editable from either the in-container shell or your local IDE. Add :ro for a read-only mount.
| Port | Service | Purpose |
|---|---|---|
8090 | llmiddler-gateway | Analysis Web UI (/_ui/) + /_ingest capture endpoint |
9090 | llmiddler-proxy | Transparent HTTP/HTTPS MITM proxy + CA cert (/ca.crt) |
9091 | llmiddler-proxy | Real-time proxy Web UI: live clients + TLS fingerprints |
8233 | Temporal | Local Temporal server UI (internal orchestration; optional) |
The gateway and the proxy each read a YAML config file. The locations are overridable via environment variables — the defaults preserve the built-in behavior, so you only set these if you bind-mount your own config:
| Variable | Default | Component |
|---|---|---|
LLMIDDLER_CONFIG | /opt/llmiddler/config.yaml | llmiddler-gateway |
LLMIDDLER_PROXY_CONFIG | /opt/llmiddler-proxy/llmiddler-proxy.yaml | llmiddler-proxy |
For example, to run the proxy with your own config file:
docker run --init \
-p 8090:8090 -p 9090:9090 -p 9091:9091 \
--env-file .env \
-e LLMIDDLER_PROXY_CONFIG=/workspace/mount/my-proxy.yaml \
-v "$PWD:/workspace/mount" \
-it --rm \
redteamsfr/llmiddler-sandbox:latest-light bash
Agents and CLIs
vibe — Mistral AI CLIopencodeclaude — Anthropic CLIconfluence-reader / confluence-writer — read from and publish to Confluencetemporal — Temporal CLILLM observability
llmiddler-proxy — transparent HTTPS proxy on port 9090 with a freshly-generated CA installed in the system trust store (served at
http://localhost:9090/ca.crt): no TLS plumbing required on the client side. Its own real-time web UI runs on port 9091 (http://localhost:9091/?t=secret) and shows live intercepted clients and their TLS fingerprints.llmiddler-gateway — ingest service and analysis UI on port 8090 (http://localhost:8090/_ui/).HTTP_PROXY / HTTPS_PROXY / SSL_CERT_FILE / REQUESTS_CA_BUNDLE / NODE_EXTRA_CA_CERTS pre-configured for Python, Go, and Node.js.No harness changes needed: as long as it honors the HTTP_PROXY / HTTPS_PROXY environment variables (which most SDKs do), it just works.
| Tag | Contents |
|---|---|
:latest-light | CLIs + proxy + gateway, no browser |
:latest | + Chromium, Camofox, Lightpanda, Playwright |
The light variant covers text-only workflows. The full image adds browsers for agents that can navigate the web.
Two flavors of tags are published, with different stability guarantees.
Pinned tags — :vX.Y.Z-light, :vX.Y.Z
Each git tag of the form vX.Y.Z triggers a build that pushes the matching Docker tag. Treat these as immutable: once published, a given vX.Y.Z[-light] tag is meant to keep referencing the same image. We do not re-publish over an existing version tag.
If you want a reproducible deployment, pin to vX.Y.Z[-light] (or to the image digest, @sha256:..., for a stronger guarantee that survives even accidental overwrites).
Floating tags — :latest-light, :latest
These are updated on every release and always point to the most recent vX.Y.Z[-light] build. Convenient for trying things out, but not recommended for any environment where you care about reproducibility.
The image follows semantic versioning: a bump in MAJOR may include breaking changes, MINOR adds features in a backwards-compatible way, PATCH is bug fixes only.
Enjoy.
This Docker image is provided free of charge for evaluation and demonstration purposes only.
You may:
You may not:
The software, Docker image, and all associated intellectual property remain the exclusive property of the copyright holder. This license does not transfer ownership of any intellectual property rights.
This software is provided "AS IS", without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement.
In no event shall the copyright holder be liable for any claim, damages, or other liability arising from or relating to the use of this software.
A commercial license is required for production use or any commercial deployment beyond evaluation. Please contact the author for licensing information.
© 2026 redteamsfr. All rights reserved.
Content type
Image
Digest
sha256:ab7351205…
Size
417.2 MB
Last updated
7 days ago
docker pull redteamsfr/llmiddler-sandbox:latest-light