Share feedback
Answers are generated based on the documentation.

sbx policy allow network

DescriptionAllow network access to specified hosts
Usagesbx policy allow network [--sandbox SANDBOX] RESOURCES [flags]

Description

Allow sandbox network access to the specified hosts.

RESOURCES is a comma-separated list of hostnames, domains, or IP addresses. Supports exact domains (example.com), wildcard subdomains (*.example.com), and optional port suffixes (example.com:443). Use "**" to allow all hosts.

The rule applies globally to all sandboxes by default. Use --sandbox to add the rule to policy "local" scoped to a single sandbox instead.

Options

OptionDefaultDescription
--sandboxScope the rule to a specific sandbox (default: all sandboxes)

Global options

OptionDefaultDescription
--cloudDispatch to Docker Cloud Sandboxes API instead of local sandboxd (supported by a growing set of verbs — run 'sbx --cloud --help' for the current list)
--cloud-api-urlhttps://api.sandboxes-cloud.docker.comCloud Sandboxes API base URL; only used with --cloud. Defaults to prod (https://api.sandboxes-cloud.docker.com). Set DOCKER_CLOUD_API_URL or pass this flag to override; a legacy value ending in /v1 is accepted.
-D, --debugEnable debug logging

Examples

# Allow access to a single host (all sandboxes)
sbx policy allow network api.example.com

# Allow access to multiple hosts
sbx policy allow network "api.example.com,cdn.example.com"

# Allow a host only for a specific sandbox
sbx policy allow network --sandbox my-sandbox api.example.com

# Allow all subdomains of a host
sbx policy allow network "*.npmjs.org"

# Allow all outbound traffic
sbx policy allow network "**"