Functions
WithSecrets()
Example
Example
CreateSandbox alongside the other options.
Parameters
secrets…SecretEntrySecret entries to attach, usually built with Secret.Env.
Returns
SandboxOption
Functional option for CreateSandbox.
Secret
TheSecret factory is a package-level value. Call its methods to build SecretEntry values without populating struct literals by hand.
Secret.Env()
Example
Example
SecretEntry that maps an environment variable to a real value. The guest sees a placeholder; the real value is substituted by the TLS proxy only when traffic goes to an allowed host. Supply at least one exact or wildcard host in Allow; an empty allow-list is rejected when the sandbox configuration is validated.
Parameters
envVarstringEnvironment variable name holding the placeholder inside the sandbox. Must be non-empty and cannot contain
= or NUL; shell-identifier syntax is not required.valuestringThe real secret value. Passed to the native host runtime, never exposed inside the guest.
optsSecretEnvOptionsAllowed hosts, placeholder override, TLS requirement, and violation action.
Returns
Pass to WithSecrets.
Validation and lifecycle
Sandbox configuration validation rejects invalid environment names (empty or containing= or NUL), an empty allow-list, all substitution locations disabled, and invalid placeholders. Secret.Env() constructs a value; errors surface when the configuration is validated.
Raw values are persisted in the durable sandbox configuration. See source references and live modification to rotate or remove secrets without restarting. Adding a secret or changing its guest-visible placeholder requires a restart. Live modification is local-only.
Types
SecretEntrystruct
accepted by WithSecrets() · returned by Secret.Env()
A single credential the network proxy substitutes at the transport layer. The value never reaches the guest VM. Usually produced bySecret.Env; exported for callers that prefer struct literals.
SecretEnvOptionsstruct
accepted by Secret.Env()
TunesSecret.Env beyond the required envVar and value.
SecretSubstitutionstruct
Used by SecretEntry · SecretEnvOptions
Use a pointer to distinguish an explicit false from the default:
Passthrough. Fixed-length HTTP/1 bodies up to 16 MiB update Content-Length; larger fixed-length bodies are blocked. Chunked bodies are decoded and re-encoded. Encoded bodies pass through unchanged. HTTP/2 DATA-frame body substitution is unsupported, and matching body placeholders are blocked.
ViolationActionstring enum
field of SecretEntry · NetworkConfig
NetworkConfig.SecretViolationAction; override per-secret with SecretEntry.ViolationAction.