Lesson 14 / 25

Network Egress Allowlists

Allow outbound traffic only to hosts the task needs and block metadata endpoints.

Control where data can go

An injected instruction usually needs to send data out (to an attacker's server) or download code in. If the agent can only reach a short list of hosts, such as your package registry and Git host, both become hard. Match the exact hostname (not a substring: pypi.org.evil.com is not pypi.org), block private and link-local addresses such as the cloud metadata service (169.254.169.254), and enforce the rule in the sandbox or a proxy, not just in the agent.

A host check, run

I ran this. The look-alike domain and the metadata IP are blocked; exact allowed hosts pass. A real deployment enforces this at the network layer.

from urllib.parse import urlparse
ALLOW = {"pypi.org", "files.pythonhosted.org", "registry.npmjs.org", "github.com"}

def egress_ok(url):
    return (urlparse(url).hostname or "") in ALLOW

for u in ("https://pypi.org/simple/x", "https://pypi.org.evil.com/x",
          "http://169.254.169.254/latest/meta-data", "https://github.com/a/b"):
    print(egress_ok(u), u)

Output:

True https://pypi.org/simple/x
False https://pypi.org.evil.com/x
False http://169.254.169.254/latest/meta-data
True https://github.com/a/b

Default to no network

Many agent tasks (editing code, running tests that are already installed) need no network at all. Start with none, and add specific hosts only when a task proves it needs them.

Quick check: Why match the exact hostname rather than "contains pypi.org"?

  • It makes no difference
  • Hostnames are case-insensitive only
  • Substring checks are faster
  • Look-alike domains such as pypi.org.evil.com would pass
Answer

Look-alike domains such as pypi.org.evil.com would pass — Attackers register domains that contain a trusted name, so only exact matches are safe.