Container with network allowlist
Container-isolated execution with an allowlist for network egress (e.g., package registries, AI endpoints only). Scoped tmpfs filesystem.
id policy/container-with-allowlistv1.0.0by convergent-systems-key
Rule
Container-isolated execution with an allowlist for network egress (e.g., package registries, AI endpoints only). Scoped tmpfs filesystem.
- Process
container- Network
allowlist- Filesystem
scoped- Paths
/workspace/tmp
Used by
- agent/runbook-executor — Runbook Executor
Author convergent-systems-key. Source convergent-systems-co/agent-atoms (original ↗). License Apache-2.0. Re-typed from isolation-constraint by scripts/migrate-policy-tool.py.