smol machines actually support exactly those things across macs,linux, windows btw: https://github.com/smol-machines/smolvm/blob/main/AGENTS.md#...
here's a snippet of how it looks like to configure that:
[network]
allow_hosts = ["api.github.com"] # hostname, also allows its subdomains
allow_host_patterns = ["example.com", "*.npmjs.org"] # exact names, or *. for subdomains only
allow_cidrs = ["10.0.0.0/8", "1.1.1.1"] # IP ranges or single IPs
[[network.credentials]]
name = "github"
environment_variable = "GITHUB_TOKEN"proxy in the middle (but cert pinning problems)
or DNS filtering? (but agent could have "memorized" stable IP)
Memorized IP: doesn't work, the vm can only connect to an IP if it came from a DNS lookup of an allowed name. Any other IP is blocked.
A bit of "shared responsibility" philosophy kicking through but I try to have good defaults
Of course, that only limits HTTP; and not other forms of network requests.
https://github.com/anthropics/sandbox-runtime/tree/main#as-a...
const config: SandboxRuntimeConfig = {
network: {
allowedDomains: ['example.com', 'api.github.com'],
deniedDomains: [],
},
filesystem: {
denyRead: ['~/.ssh'],
allowWrite: ['.', '/tmp'],
denyWrite: ['.env'],
},
}