Choose isolation settings
Combine execution, Git and network controls according to the access your task needs.
Layers you set yourself
Section titled “Layers you set yourself”Choose the execution environment first, then configure its Git, network and credential access. These controls belong to the sandbox provider and apply independently of the agent’s instructions. The local provider runs directly on your machine without isolation.
- Network restrictionsBlock all outbound traffic, or allow only the hosts the agent really needs.
- Private GitGive the container its own checkout instead of your mounted worktree.
- Environment variablesDeclare which values reach the sandbox, the agent or a single command.
- Cloud sandboxesMove the work off your machine, onto a hosted sandbox.
- Firecracker microVMsA separate guest kernel on infrastructure you operate.
- SecurityWhat each boundary covers, and what it leaves open.
Restrict a container’s access
Section titled “Restrict a container’s access”Docker and Podman take both layers at once: the container reaches no network and never sees your worktree.
Prepare the tools and dependencies in the image first. A CLI agent cut off from the network cannot reach its model; the built-in harness can, because its model requests leave from your host and only its tools run offline.
What each layer covers
Section titled “What each layer covers”| Layer | Set on | Keeps the agent away from | Available on |
|---|---|---|---|
| Egress policy | The sandbox provider | Hosts you did not allow | Docker and Podman: deny-all only; allowlists on Vercel and Daytona |
| Private Git | Docker or Podman | Your worktree and your host Git directories | Docker and Podman |
| Hosted sandbox | The provider you choose | Your filesystem, your processes | Vercel, Daytona, Firecracker |
| Declared variables | dispatch() or the provider | Values you did not declare | Every provider |
Remote providers always work on a copy of the history. Host execution isolates nothing: createLocalSandboxProvider() runs commands on your machine, and you select it explicitly.
Limits
Section titled “Limits”- A policy is fixed when the provider is created, and an allowed destination can still receive whatever the agent sends it.
- Egress does not govern traffic Outpost handles itself: harness model requests, image pulls, file transfers and cloud control-plane calls.
- Private Git protects your Git metadata, not your host. You still trust the image, the engine, the kernel and every mount you add.
- The code the agent writes comes back to your machine. Read it before you run it there.
- Nothing falls back to the host: a missing engine, SDK or credential fails the task instead.
API: EgressPolicy · ContainerOptions · VercelOptions · DaytonaOptions · createDockerSandboxProvider · createLocalSandboxProvider.