Containment
vm-7f3a
Sealed
Sandbox
Internet
Boundary
main.js
Secret
OPENAI_API_KEY
••••••••••
Secret
DATABASE_URL
••••••••••
reveal secrets
/tmp · ephemeral
0
empty · wiped on teardown
api.openai.com
allow
sdk.vercel.ai
allow
api.github.com
deny
$ tap a host to test the boundary…
write /tmp
Teardown
Allowlisted egress passes · everything else hits the wall