Networking
The network: block controls the VM’s network policy. It is baked in at VM creation, so changing it recreates the VM (see Resource Config Application). When the whole network: block is absent, the VM gets microsandbox’s default (public) — no behavior change for existing users.
| Field | Type | Description |
|---|---|---|
profile | string | public, private, host, or none. Defaults to public (microsandbox’s default) when unset. |
egress-allow | []string | Egress destinations to allow: host, a CIDR (e.g. 123.123.0.0/16), or a .suffix (e.g. .internal). |
egress-deny | []string | Egress carve-outs, same destination forms as egress-allow. Emitted before allow rules (deny-before-allow). |
profile: noneis an allowlist-only profile: egress is deny-by-default, ingress is allowed, and only the gateway-DNS rule plus your explicitegress-allow/egress-denylists apply. This is how you restrict the VM to a specific set of hosts. Thepublic/private/hostprofiles additionally allow their whole destination class.- Rule order in the generated firewall: profile rules (including gateway DNS), then
egress-deny, thenegress-allow. Soegress-allow: [123.123.0.0/16]together withegress-deny: [123.123.123.0/24]denies123.123.123.5while allowing123.123.200.5(a carve-out).
For example, to allow only a single API host:
network:
profile: none
egress-allow:
- api.example.com
Profile and lists can be combined, e.g. a private profile with an egress-allow: [.internal] exception.
The profile is also configurable via the OPENCODE_SANDBOX_NETWORK_PROFILE environment variable and the --network flag on run/shell (e.g. agents-sandbox run --network none). Precedence: flag > env > config > default. The egress-allow/egress-deny lists are config-file-only and have no env var or flag.
network:
profile: public
egress-allow: [] # host, CIDR, or .suffix
egress-deny: [] # carve-outs; emitted before allow rules