Skip to content
Français

Restrict network access

Configure supported outbound rules and understand where they apply.

Set egress on the sandbox provider to restrict outbound traffic from the sandbox. If you omit it, the provider’s network defaults apply. Check the support table before selecting a policy.

API reference: EgressPolicy.

Support depends on the provider. Outpost rejects an unsupported policy with a configuration error when you create the provider.

Providerdeny-alldomainsallowCidrsdenyCidrs
Docker, PodmanYes (network none)NoNoNo
VercelYesYesIPv4 and IPv6Yes
DaytonaYes, server-confirmedUp to 100Up to 10 IPv4, without domainsNo
Local, FirecrackerNoNoNoNo

A CLI agent in a cloud sandbox needs its model API and the registries it installs from. List each host it contacts.

import { createVercelSandboxProvider } from "@elie-laloum/outpost/providers/vercel";

const sandboxProvider = createVercelSandboxProvider({
  egress: {
    mode: "allowlist",
    domains: ["api.openai.com", "registry.npmjs.org"],
  },
});

Entries in domains follow these rules:

  • DNS names only, without scheme, path or port: api.openai.com.
  • An exact name matches that host, not its subdomains.
  • *.example.com matches subdomains; add example.com for the apex.
  • Empty allowlists, IP addresses, bare *, single-label names and partial wildcards such as api*.example.com are rejected.

Outpost adds no destination for you. Include download hosts, redirect targets, authentication endpoints and custom model URLs. When bootstrap needs broad access, preinstall the tools in an agent image instead.

Vercel enforces the policy with its native firewall.

  • Domain rules match the TLS server name (SNI). Plain HTTP needs a CIDR rule.
  • allowCidrs grant IP access on their own; a broad range bypasses your domain list.
  • denyCidrs take priority over every allow rule.
  • A CIDR-only policy still lets the sandbox resolve other DNS names.

For per-domain request rules and transforms, set Vercel’s native create.networkPolicy instead. It is outside the portable policy, and Outpost rejects a provider that sets both.

Daytona enforces sandbox-level network rules only on Tier 3 or 4 accounts with the WRITE_SANDBOXES permission.

import { createDaytonaSandboxProvider } from "@elie-laloum/outpost/providers/daytona";

const sandboxProvider = createDaytonaSandboxProvider({
  egress: { mode: "allowlist", allowCidrs: ["203.0.113.0/24"] },
});

Outpost sends the policy at creation, then applies it again through Daytona’s network API before it prepares the workspace. If Daytona refuses, acquisition fails with a provider error and Outpost deletes the sandbox.

  • Use domains or allowCidrs, not both, and no denyCidrs.
  • List at most 100 domains or 10 IPv4 CIDRs.
  • Daytona’s *.example.com also matches example.com, so Outpost requires example.com in the list too.
  • Choose egress or Daytona’s native network settings in create, including outboundProxyUrl. Native settings keep Daytona’s semantics, without Outpost’s confirmation.

Confirmation happens after the sandbox starts, so code the image launches on its own may run first. Use trusted images without startup workloads or embedded secrets. See Daytona network limits.

deny-all attaches a Docker or Podman container to the none network. Prepare tools and dependencies in the image first.

import { createDockerSandboxProvider } from "@elie-laloum/outpost/providers/docker";

const sandboxProvider = createDockerSandboxProvider({
  image: "outpost:dev",
  egress: { mode: "deny-all" },
});

A CLI agent in this sandbox cannot reach its model. The built-in harness can: its model requests leave from your host, and only its tools run offline.

Sandbox egress does not govern traffic that Outpost handles on the host:

  • Model requests from the built-in harness.
  • Image pulls and file transfers.
  • Requests to a cloud provider’s control plane.
  • A policy is fixed when you create the provider. Outpost does not change it during a run.
  • Docker and Podman enforce deny-all only; networks other than none conflict with it. For allowlists, use Vercel or a firewall you manage.
  • Local execution and Firecracker reject egress; Firecracker networking is configured on your host.
  • A cloud service can still reject a policy when Outpost acquires the sandbox.
  • Allowed destinations can still receive data from the agent.
  • Network rules do not restrict mounts, credentials or host sockets you expose to the sandbox. See Security.

API: EgressPolicy · ContainerOptions · VercelOptions · DaytonaOptions.