egressOptional
EgressPolicy | undefined
Portable policy translated to Vercel’s firewall when the provider is created: domains match the TLS server name, allowCidrs grant IP access on their own and denyCidrs take priority. Setting create.networkPolicy too fails with code configuration.
createOptional
NonNullable<(WithPrivate<((BaseCreateSandboxParams & ({ runtime?: RUNTIMES | (string & {}); image?: never; } | { runtime?: never; image?: (string & {}) | "vercel/sandbox/universal" | "vercel/sandbox/node:22" | "vercel/sandbox/node:24" | "vercel/sandbox/node:26" | "vercel/sandbox/python:3.14" | "vercel/sandbox/ubuntu" | "vercel/sandbox/arch"; })) | (Omit<BaseCreateSandboxParams, "source"> & { source: { type: "snapshot"; snapshotId: string; }; runtime?: never; image?: never; })) | (((BaseCreateSandboxParams & ({ runtime?: RUNTIMES | (string & {}); image?: never; } | { runtime?: never; image?: (string & {}) | "vercel/sandbox/universal" | "vercel/sandbox/node:22" | "vercel/sandbox/node:24" | "vercel/sandbox/node:26" | "vercel/sandbox/python:3.14" | "vercel/sandbox/ubuntu" | "vercel/sandbox/arch"; })) | (Omit<BaseCreateSandboxParams, "source"> & { source: { type: "snapshot"; snapshotId: string; }; runtime?: never; image?: never; })) & Credentials)> & WithFetchOptions) | undefined> | undefined
Options passed to Sandbox.create() from @vercel/sandbox; Outpost adds the sandbox environment to env.
variablesOptional
Readonly<Record<string, string>> | undefined
Environment variables set for every command in the sandbox, as literal values. A key the agent also declares fails with code configuration.
rootOptional
string | undefined
Repository directory inside the sandbox, default /vercel/sandbox/outpost.
retainOptional
number | undefined
Bytes of output tail kept per stream, default 65536.