Restricted tool access for Agents and Sandboxes (Beta)
Agents and Sandboxes accept network.egress.policy: AllowList with explicit DNS hosts in
network.egress.allow. The host list reaches the node’s existing proxy, which permits HTTP
and HTTPS to those hosts while blocking other destinations and private addresses.
Use this with a scoped project Secret for GitHub access. Tools must honor the injected
HTTP_PROXY and HTTPS_PROXY settings. Deny remains the default.
Sandbox programs can also call Nodus On Demand through the injected OPENAI_BASE_URL and placeholder
OPENAI_API_KEY. Nodus keeps the real credential outside the container and binds it to that Sandbox’s
project and running attempt.