Repo of the Day
openai/fence: A fence keeps things out, but also in. This project is still in early, and active development.
Published: Aug 30, 2026
Open repository ↗A fence keeps things out, but also in. This project is still in early, and active development. - openai/fence
Summary
openai/fence is a GitHub Action written in Rust that restricts outbound network traffic and tightens runner privileges during CI jobs. It is designed to limit where a workflow can send data on GitHub-hosted Ubuntu runners, helping teams reduce supply-chain risk in their CI/CD pipelines.
What it is useful for
Fence addresses a common CI gap: even when source code and dependencies are pinned, a compromised step or dependency can still exfiltrate secrets or fetch second-stage payloads from arbitrary endpoints. By default, Fence blocks outbound connections unless the hosted runner needs them, disables passwordless sudo, and disables Docker, so later steps cannot easily reach unexpected destinations or escalate privileges.
It is useful when teams want egress filtering for GitHub Actions, tighter runner lockdown, or an audit trail of what network activity a job attempted. After the job, Fence adds a network activity table to the job summary and writes a FENCE_REPORT_JSON= line to the post-job log, which the README shows can be retrieved with gh api for downstream review.
How engineers can use it
The README documents a quick-start pattern. Add openai/fence@<commit-sha> as the first step in a Linux job, before checkout and any other work:
jobs:
test:
runs-on: ubuntu-24.04
steps:
- uses: openai/fence@<commit-sha>
- uses: actions/checkout@<checkout-commit-sha>
- run: script/test
The README recommends pinning to the full commit SHA from a published release rather than main.
For jobs that need specific external endpoints, add an allowlist with up to 64 entries. Bare hostnames default to TCP port 443, and Fence also supports custom ports, UDP, CIDR ranges, IPv6, and one- or two-level host wildcards, for example registry.example.com:8443 or cidr 192.0.2.0/24 udp 123. Engineers unsure which destinations their job needs can first run with mode: audit, which logs blocked activity without enforcing it, then build an allowlist from the suggested entries in the report.
When jobs must upload artifacts or publish Pages, allow_github_artifacts: true re-enables limited access to GitHub Actions storage. If a job needs containers, container_policy: unsafe_preserve keeps Docker available, but the README warns this reduces isolation.
Documented limitations include support only for GitHub-hosted ubuntu-24.04 and ubuntu-latest x64 runners, that Fence is explicitly not a full sandbox, and that the Azure Instance Metadata Service at 169.254.169.254:80 remains reachable. If startup fails, the README points readers to inspection reason codes in its troubleshooting guide.