Skip to main content
By default a machine can reach anything on the internet. An egress allowlist narrows that to the hosts and addresses you name. Everything else is refused at the edge of the machine, before it leaves the host. The allowlist is set from the outside: the machine’s Networking tab in the console, boxd machine egress on the CLI, or the SDKs. There is deliberately no way to change it from inside the machine. A process with root in the machine cannot widen its own allowlist.

Entries

An entry is one of: HTTP and HTTPS are admitted by hostname. Everything else, an SSH connection or a database port for example, is admitted by address. Provider-wide wildcards such as *.amazonaws.com are refused. The hosts of any host-bound secret the machine holds are always admitted, on top of the list, so a secret bound to api.stripe.com keeps working under an allowlist that does not name it.

Set it

The list you pass is the complete new allowlist, not an addition. An empty allowlist means unrestricted. In the console, open the machine, then Networking, then Edit next to the egress allowlist. The change takes effect immediately, without a reboot, and shows up on every surface at once.

From the SDKs

What it is for

An allowlist turns a machine into a place where an agent or a job can run with a known set of destinations: the model provider, your own API, the package registry. Combine it with an isolated machine and with host-bound secrets, and the machine can neither reach what it should not nor leak a credential to where it should not go.