Skip to main content
Configure one HTTP CONNECT, SOCKS4, or SOCKS5 proxy for outbound sandbox traffic. The guest connects to its normal destination; microsandbox routes eligible traffic through the proxy on the host. Set sandbox_defaults.outbound_proxy in global configuration for a shared default. Administrators can enforce or clear it through managed configuration, which takes precedence over per-sandbox CLI and SDK options.

Supported proxies

You can configure only one proxy for a sandbox. A SOCKS4 user ID identifies the caller; it is not a password.

Configure a proxy

SDK addresses use IP:port. The msb run and msb create commands accept --proxy http://IP:port, socks4://IP:port, or socks5://IP:port. Proxy URIs reject user information, paths, query parameters, and fragments; SOCKS authentication uses separate CLI flags.

HTTP CONNECT

HTTP CONNECT opens a TCP tunnel through an HTTP proxy. It does not support proxy authentication or UDP. microsandbox resolves and checks the destination using its normal DNS and egress policy before sending the destination IP and port in the CONNECT request. The proxy address itself must be an IP address with a port. The selected msb runtime must support HTTP CONNECT. When using an older runtime, the SDK requests an upgrade before creating or replacing a sandbox.

SOCKS4 user ID

Add an optional user ID through an SDK or --socks4-user-id in the CLI.
The user ID must contain 1–255 bytes and cannot contain a null byte. Omit it to use SOCKS4 without a user ID.

SOCKS5 credentials

SOCKS5 supports optional username/password authentication. Passwords are loaded from a host environment variable rather than placed directly in configuration.
  • Password source: Set the password in a host environment variable, the only supported source. Configuration stores only the variable name, such as SOCKS5_PASSWORD, never the password.
  • When changes apply: The password is read when the sandbox starts. Restart the sandbox after changing it.
  • Requirements: The username and password must each contain 1–255 bytes. Startup fails if the password variable is missing, empty, or invalid.
SOCKS5 authentication does not encrypt credentials in transit. Use a trusted local or private proxy, or encrypt the connection separately.

Behavior and limits

  • Network policy is evaluated against the sandbox’s actual destination before the proxy connection is opened.
  • HTTP CONNECT and SOCKS4 support TCP only. Non-DNS UDP is blocked while either is configured; SOCKS4 also cannot reach IPv6 destinations.
  • SOCKS5 uses CONNECT for TCP and UDP ASSOCIATE for non-DNS UDP.
  • DNS uses microsandbox’s DNS forwarder instead of the configured proxy. This includes plain DNS, DNS-over-TCP, and DNS-over-TLS.
  • Connections to host.microsandbox.internal bypass the proxy and continue to target the microsandbox host.
  • Each TCP connection opens its own proxy connection and handshake. Each UDP flow opens its own SOCKS5 control connection and UDP association.
  • TLS interception and secret injection continue to work as configured.

Reference

For exact proxy APIs, see TypeScript, Rust, Python, or Go. For CLI flags, see Sandbox commands.