Restricted tool access for Agents and Sandboxes (Beta)

Agents and Sandboxes accept network.egress.policy: AllowList with explicit DNS hosts in network.egress.allow. The host list reaches the node’s existing proxy, which permits HTTP and HTTPS to those hosts while blocking other destinations and private addresses.

Use this with a scoped project Secret for GitHub access. Tools must honor the injected HTTP_PROXY and HTTPS_PROXY settings. Deny remains the default.

Sandbox programs can also call Nodus On Demand through the injected OPENAI_BASE_URL and placeholder OPENAI_API_KEY. Nodus keeps the real credential outside the container and binds it to that Sandbox’s project and running attempt.