EgressPolicy
Parameters and properties
Section titled “Parameters and properties”The fields below cover all variants; the signature specifies their allowed combinations.
modeRequired"deny-all" | "allowlist"deny-all blocks all outbound traffic and takes no other field; allowlist allows only the listed domains and allowCidrs and needs at least one entry. A provider that cannot enforce the policy rejects it with code configuration at creation.domainsVariant-dependentreadonly string[] | undefinedAllowed DNS names, exact or *.-prefixed for subdomains, without scheme, path or port; IP addresses and single-label names are rejected. Outpost adds no destination for you, and Daytona requires the apex of each wildcard in the list.allowCidrsVariant-dependentreadonly string[] | undefinedIP ranges allowed regardless of domains, so a broad range bypasses the domain list. Vercel accepts IPv4 and IPv6; Daytona accepts at most 10 IPv4 ranges and no domains alongside them.denyCidrsVariant-dependentreadonly string[] | undefinedIP ranges blocked even when a domain or allowCidrs entry allows them. Only Vercel enforces them; Daytona rejects a non-empty list.