pub enum SandboxEgress {
Deny,
Allow,
AllowDomains {
domains: Vec<String>,
},
}Expand description
Outbound network policy for a sandbox.
Variants§
Deny
No outbound network access.
Routed traffic only. Link-local is not outbound and no backend’s egress control reaches it, so this is not a boundary against instance metadata.
Nor, on AWS, against DNS: while the connector VPC has DNS support on, a session resolves names through that VPC’s resolver, which no security group filters, so a query name can carry data out.
Allow
Unrestricted outbound access to the public internet, and none to private ranges or the deployment’s own network.
Link-local carries the same exception as Deny. AWS and Kubernetes deliver both halves.
Azure and GCP deliver the first only: one matches host patterns and the other is a single
switch, so neither can name an address range to exclude.
AllowDomains
Outbound access only to the listed hostnames.
Azure alone expresses it: its egress proxy matches on host pattern. The others filter by CIDR or carry a single switch, and both would approximate the list rather than keep it.
Implementations§
Source§impl SandboxEgress
impl SandboxEgress
Sourcepub fn internet_access_switch(&self) -> Option<bool>
pub fn internet_access_switch(&self) -> Option<bool>
The single outbound switch for a backend that has no host matcher, or None for a mode a
boolean cannot carry.
AllowDomains needs a host list, so it maps to nothing and each caller refuses it in its
own error naming the sandbox. One source for what a mode means, so a template and a sandbox
cannot disagree on it.
Trait Implementations§
Source§impl Clone for SandboxEgress
impl Clone for SandboxEgress
Source§impl Debug for SandboxEgress
impl Debug for SandboxEgress
Source§impl<'de> Deserialize<'de> for SandboxEgress
impl<'de> Deserialize<'de> for SandboxEgress
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for SandboxEgress
Source§impl PartialEq for SandboxEgress
impl PartialEq for SandboxEgress
Source§impl Serialize for SandboxEgress
impl Serialize for SandboxEgress
impl StructuralPartialEq for SandboxEgress
Auto Trait Implementations§
impl Freeze for SandboxEgress
impl RefUnwindSafe for SandboxEgress
impl Send for SandboxEgress
impl Sync for SandboxEgress
impl Unpin for SandboxEgress
impl UnsafeUnpin for SandboxEgress
impl UnwindSafe for SandboxEgress
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.