Innerwall
Pre-release · v0.1.0 in progressOpen-source microsegmentation for VMs, bare metal, and cloud instances.
Innerwall is an open-source microsegmentation platform I'm building. A small agent on each workload observes network flows and programs the operating system's native firewall. A central control plane turns label-based policy into per-host rulesets, streams them to the agents, and shows the estate's actual traffic as a live dependency map. No orchestrator required.
Source on GitHub →Apache-2.0
How it rolls out: visibility → simulate → enforce
1. Visibility
Agents report the connections each workload actually makes. The control plane resolves them to workloads and labels and builds a dependency map. Nothing is blocked.
2. Simulate
Policy compiles to the same host rules it will enforce, but with an accept at the end. Traffic that would have been dropped is logged and rolled up per ruleset, so you can review the impact before anything changes.
3. Enforce
Once simulation shows nothing unexpected would be dropped, workloads are promoted to enforcement. Rules are applied atomically and persist locally if the control plane goes offline.
Design
- Single control-plane binary plus PostgreSQL
- Agents enroll with a scoped provisioning token and run on short-lived mTLS certificates
- Programs the host's existing firewall atomically instead of shipping a custom datapath
- Operator console for the flow map, simulation review, and policy authoring