Vouch request: hugoch #3834
Hugoch
started this conversation in
Vouch Request
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What do you want to work on?
Egress usage monitoring for individual sandboxes and fleets. The change would allow the supervisor to monitor each sandbox egress endpoint: connection count, requests, read/write requests, total bytes in/out and response classes.
The feature would allow to setup limits as part of policy (max bytes, rate-limit..) and report drift findings when endpoint usage changes against the baseline of the sandbox.
Why this change?
OpenShell allows control of network egress by limiting destination hosts and, for HTTP, the allowed methods. While this ensures communication only to the allowlisted hosts, it does not protect against abuse of the remote destination. The recent example of OAI agents using their software repository to access the internet shows that a legitimate destination can be abused without breaking egress rules. The proposed feature helps catch misbehavior as part of OpenShell tooling rather than relying on a more complex SIEM setup.
Checklist
All reactions