kosa8 docs

Commands / kosa8 sandbox egress

kosa8 sandbox egress

Show the egress policy the host enforces for a sandbox, and what it has refused

Usage

kosa8 egress SANDBOX

The sandbox's egress policy is enforced on the host, in the userspace network every frame from the VM passes through, so root in the guest cannot lift it. This shows the policy and the counts since the sandbox booted; each refused attempt is also in the audit log as sandbox.egress.deny (rate-limited, with a count of any held back).