You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(api): SOCKS5 egress proxy on sandbox network config (BYOP) (#2642)
Sandboxes have two related egress problems we cannot solve from our
side: operators want a predictable egress identity (their public IP,
not ours), and they want sandboxes to reach hosts that are reachable
from their own proxy server — corporate networks, VPN endpoints,
internal LAN. This PR adds Bring-Your-Own-Proxy: an optional
`egressProxy: {address, username, password}` on the sandbox network
config tunnels all sandbox TCP egress through a user-supplied SOCKS5
server, with our allow/deny rules still applied before the tunnel.
Scope here is the API + orchestrator plumbing: OpenAPI, DB types,
proto, the API create/get handlers (password omitted from GET), the
`BYOPProxyEnabledFlag` LD gate, and a validator that rejects a SOCKS5
endpoint pointing at our own infra at create time and re-checks on
every dial (DNS-rebind guard). For BYOP-enabled sandboxes only, the
sandbox-netns kernel firewall is narrowed on demand so TCP destined
for the user's internal networks reaches the userspace egress proxy
instead of being dropped — without this the user's LAN destinations
would never make it past the kernel. Non-BYOP sandboxes keep the
existing hard kernel drop.
---------
Co-authored-by: Jakub Novák <jakub@e2b.dev>
0 commit comments