Internet access and egress
Default network behavior
- Inbound. A sandbox is not reachable from the internet. Only the ports you expose as a preview accept traffic, and only through the MIOSA proxy.
- Outbound. A new sandbox can reach the internet, and every outbound request is recorded. It starts in audit-only mode: calls are logged, none are blocked. A Computer’s network policy defaults to
unrestricted.
So by default your code can install packages, call APIs, and clone repos. Nothing is blocked until you choose to enforce an allowlist.
Two layers of control
MIOSA gives you two ways to constrain outbound traffic. They compose.
| Layer | Scope | What it decides |
|---|---|---|
| Egress policy + allowlist | Computers and Sandboxes | The hosts a resource may reach, in audit_only or enforce mode |
| Network policy | Computers | A microVM-level mode: unrestricted, allowlist, denylist, or isolated |
A Computer or Sandbox resolves its egress policy as: resource override, then tenant default. The tenant default starts in audit_only mode.
Watch, then enforce
The intended path for a sandbox is to observe real traffic, then lock it down to what it actually uses. This is the same flow documented in full on the network allowlist reference:
- Observe. Let the sandbox run normally. Every outbound host is recorded.
- Review. Pull the hosts it contacted, ranked by frequency.
- Enforce. Apply those hosts as the allowlist and switch the policy to
enforce. Unlisted hosts are then blocked. - Operate. Blocked hosts land in a pending queue with one-click allow or deny. Revert to audit-only at any time without losing the allowlist.
Allowlist rules
| Kind | Example | Matches |
|---|---|---|
| Exact host | api.openai.com | Only this hostname |
| Wildcard | *.openai.com | Any subdomain of openai.com |
| CIDR | 10.0.0.0/8 | Any IP in this range, when the target is an IP literal |
Rules are matched in priority order: exact beats wildcard, wildcard beats CIDR, and an explicit deny always beats an allow. A rule can be scoped to a method and a path, and marked warn_only to let the request through while flagging it in the audit log.
Rules attach at two levels: per-resource (one sandbox or computer) and tenant-wide (every resource unless overridden).
Restrict a Computer at the microVM level
Computers also accept a network policy that takes effect within seconds, without a restart.
| Mode | Description |
|---|---|
unrestricted | Default. All outbound traffic allowed |
allowlist | Only listed hosts and ports permitted |
denylist | All traffic allowed except listed rules |
isolated | All outbound blocked (DNS and MIOSA internal excluded) |
A PUT replaces the whole policy; send every rule on every call. DELETE resets it to unrestricted.
Credentials on the way out
Egress is also where MIOSA swaps placeholders for real credentials. Your workload sees an opaque miosa-tok-... value in its environment; the proxy substitutes the real secret on the outbound request, so the value never lives inside the sandbox. See Secrets and the Egress API.
Debug a blocked call
Common allowlist gaps:
pip installneedspypi.org,files.pythonhosted.org, andpythonhosted.org.npm installneedsregistry.npmjs.org; some postinstall scripts also reach*.github.com.- CDNs and dynamic subdomains are usually not covered by an exact rule. Use a wildcard like
*.openai.com.
Every blocked row carries a rejected_by field naming the rule that fired. For the full list of fixes, see Security troubleshooting.