sbx policy allow network
| 内容説明 | Allow network access to specified hosts |
|---|---|
| 利用方法 | sbx policy allow network [--sandbox SANDBOX] RESOURCES [flags] |
Description
Allow sandbox network access to the specified hosts.
RESOURCES is a comma-separated list of hostnames, domains, IP addresses, or CIDR prefixes. Rules apply to TCP by default; use --protocol to select UDP or both transports. Supports exact domains (example.com), wildcard subdomains (.example.com), multi-label wildcards (.example.com), single-character globs (api?.example.com), character classes (api[12].example.com, api[!1].example.com), and optional port suffixes (example.com:443). An IPv6 address takes a port in brackets ([2001:db8::1]:443) or a CIDR prefix (2001:db8::1/128); a bare one is refused. Use "" to allow all hosts. A bare "", an escaped glob character such as "*", and any other pattern outside these forms are rejected rather than stored as a rule that matches nothing.
The rule applies globally to all sandboxes by default. Use --sandbox to add the rule to policy "local" scoped to a single sandbox instead.
Options
| オプション | デフォルト | 内容説明 |
|---|---|---|
--protocol | Network protocol: tcp or udp; repeat or comma-separate for both | |
--sandbox | Scope the rule to a specific sandbox (default: all sandboxes) |
Global options
| オプション | デフォルト | 内容説明 |
|---|---|---|
--cloud | Dispatch to Docker Cloud Sandboxes API instead of local sandboxd (supported by a growing set of verbs — run 'sbx --cloud --help' for the current list) | |
-D, --debug | Enable debug logging |
Examples
# Allow access to a single host (all sandboxes)
sbx policy allow network api.example.com
# Allow access to multiple hosts
sbx policy allow network "api.example.com,cdn.example.com"
# Allow a host only for a specific sandbox
sbx policy allow network --sandbox my-sandbox api.example.com
# Allow all subdomains of a host
sbx policy allow network "*.npmjs.org"
# Allow all outbound traffic on both transports
sbx policy allow network --protocol tcp,udp "**"