Network egress
Choose what a sandbox may reach on the network, from the whole internet to an allowlist of addresses or nothing at all.
Every sandbox has an outbound network policy. You choose it when you create or fork the sandbox, and it cannot be changed afterwards.
| Mode | The sandbox can reach |
|---|---|
default |
the public internet |
allowlist |
only the IPv4 and IPv6 prefixes you list |
none |
nothing |
pols new --name web # default: the public internet
pols new --name locked --egress allowlist --allow 203.0.113.10/32 --allow 2001:db8::/32
pols new --name offline --egress none
pols fork web --name web-offline --egress none # a fork may choose its own policy
A fork keeps its source’s policy unless you set one. Over the API, pass egress with mode and, for an allowlist, allow (up to 64 CIDR prefixes) to POST /v1/sandboxes or .../fork.
How the modes behave
- The policy filters by IP address, not by host name. To allow a service, list the addresses or prefixes it uses. Single addresses need
/32(IPv4) or/128(IPv6). - In
allowlistandnone, the sandbox has no DNS resolver. For DNS in allowlist mode, allow a public resolver’s address and configure the sandbox to use it, for example in/etc/systemd/resolved.conf. - A policy applies to new connections.
Pick the mode with the sandbox’s purpose in mind: none suits running untrusted code on data you copied in, allowlist suits a sandbox that should talk to one API or one database.
Blocked in every mode
Some destinations are blocked whatever the policy says, and an allowlist entry that overlaps the built-in ranges is refused:
- other sandboxes, including your own;
- the sandbox host and the pols infrastructure, including
api.pols.so,ssh.pols.soand*.on.pols.so, so the pols CLI and published ports cannot be used from inside a sandbox; - private (RFC 1918), CGNAT and link-local addresses on the network, including the cloud metadata address
169.254.169.254, and IPv6 unique-local and link-local addresses; - multicast and broadcast;
- outgoing SMTP on TCP port 25. To send email from a sandbox, use your mail provider’s submission port or HTTP API.
Incoming traffic
Nothing on the internet can open a connection to a sandbox directly. The only ways in are the ones pols provides, and they work in every egress mode: published ports and SSH through the edge, and the desktop, commands, file transfers and computer use through the control plane.