Skip to content

Document scoped network policies for sbx#24978

Open
dvdksn wants to merge 2 commits intodocker:mainfrom
dvdksn:docs/sbx-scoped-kit-policies
Open

Document scoped network policies for sbx#24978
dvdksn wants to merge 2 commits intodocker:mainfrom
dvdksn:docs/sbx-scoped-kit-policies

Conversation

@dvdksn
Copy link
Copy Markdown
Contributor

@dvdksn dvdksn commented May 6, 2026

Summary

Document sandbox-scoped network policy behavior for Sandboxes kits, including kit-level deniedDomains, scoped sbx policy [cmd] [sandbox] examples, and the updated sbx policy ls output shape.

Also fixes a small formatting issue in the policy reset section.

https://deploy-preview-24978--docsdocker.netlify.app/ai/sandboxes/security/policy/

Generated by Codex

@netlify
Copy link
Copy Markdown

netlify Bot commented May 6, 2026

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit af45e3c
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/69fdc7f0377b2400089ec00b
😎 Deploy Preview https://deploy-preview-24978--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dvdksn dvdksn force-pushed the docs/sbx-scoped-kit-policies branch 2 times, most recently from 373fd11 to a12f5fd Compare May 7, 2026 08:25
Kit network policy docs did not cover sandbox-scoped rules or kit-level deniedDomains.

Update the Sandboxes policy and kits pages with scoped policy examples, deniedDomains guidance, and a small policy page formatting fix.

Co-Authored-By: Codex <noreply@openai.com>
@dvdksn dvdksn force-pushed the docs/sbx-scoped-kit-policies branch from a12f5fd to dcffd19 Compare May 7, 2026 09:36
@dvdksn dvdksn added this to the sbx/v0.28.4 milestone May 7, 2026
@dvdksn dvdksn marked this pull request as ready for review May 7, 2026 13:00
Copy link
Copy Markdown

@docker-agent docker-agent left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🔴 CRITICAL

The documentation changes in the markdown files look accurate and well-written — the new deniedDomains field, -g/--global flag, and sandbox-scoped policy examples are clearly documented. However, all four data/sbx_cli/*.yaml files modified in this PR are auto-generated CLI reference data (matching the data/*/*.yaml pattern flagged as auto-generated in the project guidelines). These files should be regenerated from the upstream CLI source rather than edited manually. See inline comments.

Findings summary:

  • 🔴 4× HIGH — data/sbx_cli/*.yaml files hand-edited (should be regenerated from upstream)

Comment thread data/sbx_cli/sbx_policy_allow_network.yaml
Comment thread data/sbx_cli/sbx_policy_deny_network.yaml
Comment thread data/sbx_cli/sbx_policy_ls.yaml
Comment thread data/sbx_cli/sbx_policy_rm_network.yaml
@dvdksn dvdksn requested a review from a team May 7, 2026 13:13
@dvdksn dvdksn added the status/review Pull requests that are ready for review label May 7, 2026
@dvdksn dvdksn changed the title Document scoped network policies for Sandboxes kits Document scoped network policies for sbx May 7, 2026
Copy link
Copy Markdown

@docker-agent docker-agent left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟡 NEEDS ATTENTION

2 medium-severity documentation issues found in the new sbx policy ls output section. No high-severity issues, no vendored file edits flagged, no missing redirects.

Comment thread content/manuals/ai/sandboxes/security/policy.md
Comment thread content/manuals/ai/sandboxes/security/policy.md Outdated
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Copy link
Copy Markdown
Member

@usha-mandya usha-mandya left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status/review Pull requests that are ready for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants