Networking
The network: block controls the VM’s network policy. It is baked in at VM creation, so changing it recreates the VM (see Resource Config Application). When the whole network: block is absent, the VM uses the none profile and denies egress by default.
| Field | Type | Description |
|---|---|---|
profile | string | public, private, host, or none. Defaults to none (deny-by-default) when unset. |
egress-allow | []string | Egress destinations to allow: host, a CIDR (e.g. 123.123.0.0/16), or a .suffix (e.g. .internal). |
egress-deny | []string | Egress carve-outs, same destination forms as egress-allow. Emitted before allow rules (deny-before-allow). |
dns-servers | []string | DNS upstream resolvers: a bare IP (auto-appends :53) or host:port. Overrides microsandbox’s default resolver. |
profile: noneis an allowlist-only profile: egress is deny-by-default, ingress is allowed, and only the gateway-DNS rule plus your explicitegress-allow/egress-denylists apply. This is how you restrict the VM to a specific set of hosts. Thepublic/private/hostprofiles additionally allow their whole destination class.- Rule order in the generated firewall: profile rules (including gateway DNS), then
egress-deny, thenegress-allow. Soegress-allow: [123.123.0.0/16]together withegress-deny: [123.123.123.0/24]denies123.123.123.5while allowing123.123.200.5(a carve-out).
For example, to allow only a single API host:
network:
profile: none
egress-allow:
- api.example.com
Profile and lists can be combined, e.g. a private profile with an egress-allow: [.internal] exception.
The profile is also configurable via the OPENCODE_SANDBOX_NETWORK_PROFILE environment variable and the --network flag on run/shell (e.g. agents-sandbox run --network public). Precedence: flag > env > config > default. The egress-allow/egress-deny lists are config-file-only and have no env var or flag.
dns-servers sets custom DNS upstreams for the VM’s in-VM resolver. Bare IPs (IPv4 or IPv6) get :53 appended; a host:port / ip:port form is used as-is. An empty entry, a host without a port, or garbage is rejected at config-load time. It is also configurable via the OPENCODE_SANDBOX_NETWORK_DNS_SERVERS environment variable (comma-separated, e.g. 1.1.1.1,8.8.8.8) and the --dns flag on run/shell (comma-separated or repeated). Precedence: flag > env > config. A policy that sets only dns-servers (no profile) still gets the default none profile.
network:
profile: none
egress-allow: [] # host, CIDR, or .suffix
egress-deny: [] # deny entries; emitted before allow rules
dns-servers: # custom upstream resolvers (default: microsandbox's)
- 1.1.1.1
- 8.8.8.8:5353
With profile: none, only the gateway DNS is auto-allowed, so a custom resolver’s IP must also be listed in egress-allow (e.g. egress-allow: [1.1.1.1]) for DNS lookups to reach it.