Restrict network access
Configure supported outbound rules and understand where they apply.
Choose a policy
Section titled “Choose a policy”Set egress on the sandbox provider to restrict outbound traffic from the sandbox. If you omit it, the provider’s network defaults apply. Check the support table before selecting a policy.
API reference: EgressPolicy.
Support depends on the provider. Outpost rejects an unsupported policy with a configuration error when you create the provider.
| Provider | deny-all | domains | allowCidrs | denyCidrs |
|---|---|---|---|---|
| Docker, Podman | Yes (network none) | No | No | No |
| Vercel | Yes | Yes | IPv4 and IPv6 | Yes |
| Daytona | Yes, server-confirmed | Up to 100 | Up to 10 IPv4, without domains | No |
| Local, Firecracker | No | No | No | No |
Allow model APIs and registries
Section titled “Allow model APIs and registries”A CLI agent in a cloud sandbox needs its model API and the registries it installs from. List each host it contacts.
Entries in domains follow these rules:
- DNS names only, without scheme, path or port:
api.openai.com. - An exact name matches that host, not its subdomains.
*.example.commatches subdomains; addexample.comfor the apex.- Empty allowlists, IP addresses, bare
*, single-label names and partial wildcards such asapi*.example.comare rejected.
Outpost adds no destination for you. Include download hosts, redirect targets, authentication endpoints and custom model URLs. When bootstrap needs broad access, preinstall the tools in an agent image instead.
Vercel specifics
Section titled “Vercel specifics”Vercel enforces the policy with its native firewall.
- Domain rules match the TLS server name (SNI). Plain HTTP needs a CIDR rule.
allowCidrsgrant IP access on their own; a broad range bypasses your domain list.denyCidrstake priority over every allow rule.- A CIDR-only policy still lets the sandbox resolve other DNS names.
For per-domain request rules and transforms, set Vercel’s native create.networkPolicy instead. It is outside the portable policy, and Outpost rejects a provider that sets both.
Daytona specifics
Section titled “Daytona specifics”Daytona enforces sandbox-level network rules only on Tier 3 or 4 accounts with the WRITE_SANDBOXES permission.
Outpost sends the policy at creation, then applies it again through Daytona’s network API before it prepares the workspace. If Daytona refuses, acquisition fails with a provider error and Outpost deletes the sandbox.
- Use
domainsorallowCidrs, not both, and nodenyCidrs. - List at most 100 domains or 10 IPv4 CIDRs.
- Daytona’s
*.example.comalso matchesexample.com, so Outpost requiresexample.comin the list too. - Choose
egressor Daytona’s native network settings increate, includingoutboundProxyUrl. Native settings keep Daytona’s semantics, without Outpost’s confirmation.
Confirmation happens after the sandbox starts, so code the image launches on its own may run first. Use trusted images without startup workloads or embedded secrets. See Daytona network limits.
Run a container offline
Section titled “Run a container offline”deny-all attaches a Docker or Podman container to the none network. Prepare tools and dependencies in the image first.
A CLI agent in this sandbox cannot reach its model. The built-in harness can: its model requests leave from your host, and only its tools run offline.
Sandbox egress does not govern traffic that Outpost handles on the host:
- Model requests from the built-in harness.
- Image pulls and file transfers.
- Requests to a cloud provider’s control plane.
Limits
Section titled “Limits”- A policy is fixed when you create the provider. Outpost does not change it during a run.
- Docker and Podman enforce
deny-allonly;networksother thannoneconflict with it. For allowlists, use Vercel or a firewall you manage. - Local execution and Firecracker reject
egress; Firecracker networking is configured on your host. - A cloud service can still reject a policy when Outpost acquires the sandbox.
- Allowed destinations can still receive data from the agent.
- Network rules do not restrict mounts, credentials or host sockets you expose to the sandbox. See Security.
API: EgressPolicy · ContainerOptions · VercelOptions · DaytonaOptions.