Skip to content

docs(policy): clarify sandbox-local loopback access - #3740

Merged
drew merged 1 commit into
mainfrom
codex/3737-clarify-loopback-docs
Sep 26, 2026
Merged

drew merged 1 commit into
mainfrom
codex/3737-clarify-loopback-docs

Conversation

@drew

@drew drew commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator

Summary

Clarify that OpenShell's always-blocked destination ranges apply to policy-governed outbound endpoints. Workloads can still connect to sandbox-local services on loopback, as reported in #3737.

Related Issue

Closes #3737

Changes

  • Scope the loopback, link-local, and unspecified-address restriction in the network rules and policy schema docs.
  • Clarify that the resolves to always-blocked address log reason comes from the outbound policy path.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated (documentation-only change)
  • E2E tests added/updated (documentation-only change)
  • mise run ci attempted. Lint passed with a fresh Go lint cache; Go gateway tests fail because the host's /etc/openshell/gateways/default registration appears in test cases that expect only temporary user gateways.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (no behavior or architecture change)

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@github-actions

Copy link
Copy Markdown

@drew
drew added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit 2f1ea65 Sep 26, 2026
74 checks passed
@drew
drew deleted the codex/3737-clarify-loopback-docs branch September 26, 2026 18:29
@drew drew added this to the OpenShell 0.1.2 milestone Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants