Expand description
Curated network allowlist for VT Code’s agent egress.
The allowlist is loaded from a TOML file shipped with the crate (see
data/network_allowlist.toml) and organized by category. Categories
include AI provider endpoints, web & specialized search, web-crawl
helpers (Jina, Defuddle, Firecrawl, etc.), MCP servers, package
registries, code-hosting platforms, OAuth/identity, dev-infrastructure,
and OS-update mirrors.
The TOML is the source of truth; the Rust types in this module are
derived from the on-disk shape so we can also expose the per-category
lists (e.g., for diagnostics or for the agent prompt to describe
“where you can fetch from”). The flat all_allow_domains() view
collapses every category into one deduped Vec<String> and is what
the WebFetchConfig defaults consume.
The allowlist also supports a verify = true flag per entry. Entries
with that flag are surfaced via NetworkAllowlist::unverified_entries
so a startup hook can warn the operator before they’re used.
Structs§
- AiProvider
Categories - AI provider entries split into cloud vs. local/self-hosted.
- Allowlist
Entry - A single allowlist row.
- Allowlist
Meta - Allowlist file-level metadata.
- Local
AiProvider Entry - Local/self-hosted AI provider — identified by
host+portrather than a public domain. The allowlist tracks these for diagnostics; the agent sandbox already permitslocalhosttraffic via separate config. - Network
Allowlist - Top-level allowlist document.
- Search
Categories - Search entries split into generic web vs. specialized/vertical.