Core services
Backing services for this module are PostgreSQL 15+ (primary datastore) and Kafka 3.x (event bus for the audit-log pipeline consumed by
bg-log-writer). Each can be containerized or an existing external instance.
Proxy network position
Because the proxy is what ultimately relays approved traffic to external destinations, its outbound reachability is the critical networking decision for this module. There are two supported positions:- Option A — Direct egress
- Option B — Upstream proxy chain
Position
bg-proxy-server on a network segment with outbound internet access (directly or via NAT / egress gateway). Outbound access is required to the destinations being inspected — external web endpoints and/or LLM provider endpoints — typically on TCP 80 and 443. No additional proxy configuration is required.Internal connectivity
- All guard microservices and the Service Engine are internal-only and require no outbound internet access.
bg-icap-servermust be reachable frombg-proxy-serveron the ICAP port (1344) and HTTP port (8080).bg-management-panel-berequires connectivity to PostgreSQL and Kafka.- During installation, outbound access to the image repository (and Helm repository for Helm deployments) is required to pull artifacts — mirrorable to an internal registry in restricted environments.
Mail interception
In addition to HTTP/proxy traffic, BeyondGuard can monitor email via IMAP, Microsoft Exchange, and POP connectors, bringing mail-borne content under the same policy engine as the rest of your AI traffic.Related
Architecture Overview
Where the proxy and ICAP layers sit in the stack.
On-Prem Requirements
Backing services and network prerequisites.
Guard Gateway API
The API-based integration path.
Installation
Deploy the proxy and ICAP services.