Skip to main content
Configure secret substitution for outbound requests. See Secrets for usage and security concepts.

Secret

Secret.env()

Create a secret entry that maps an environment variable to a real value. The guest sees a placeholder; the real value is only substituted by the TLS proxy when traffic goes to an allowed host. Pass the returned entry to Sandbox.create(..., secrets=[...]).

Parameters

env_varstr
Environment variable name. Must be non-empty and cannot contain = or NUL; shell-identifier syntax is not required.
valuestr
The real secret value. Never enters the guest VM. Keyword-only and required.
allow_hostsSequence[str]
Hosts allowed to receive the real value (exact match). At least one exact or wildcard host is required. Default ().
allow_host_patternsSequence[str]
Wildcard host patterns, e.g. “*.googleapis.com”. Default ().
placeholderstr | None
Custom placeholder string: non-empty, up to 1024 bytes, no NUL/CR/LF. Auto-generated as $MSB_<env_var> when None. Default None.
require_tlsbool
Only substitute on TLS-intercepted connections. Disable only if you know the traffic is safe. Default True.
Per-secret violation behavior. Default ViolationAction.BLOCK_AND_LOG.
injectionSecretInjection | None
Where in the HTTP request to substitute. None uses SecretInjection() defaults. Default None.

Returns

Secret entry for Sandbox.create(secrets=[…]).

ViolationPolicy

Used by Secret.env() · SecretEntry.on_violation

Secret violation behavior, including optional passthrough hosts. Construct it with the classmethods (block(), block_and_log(), block_and_terminate(), passthrough()) rather than setting fields directly.

policy.fallback

ViolationAction · Default: BLOCK_AND_LOG Action for hosts not covered by the passthrough set

policy.passthrough_hosts

tuple[str, ...] · Default: () Exact hosts forwarded with the placeholder unchanged

policy.passthrough_host_patterns

tuple[str, ...] · Default: () Wildcard patterns forwarded with the placeholder unchanged

policy.passthrough_all_hosts

bool · Default: False Forward the placeholder unchanged to every host on_violation (per secret) and Network.on_secret_violation (sandbox-wide default) both accept a bare ViolationAction or a ViolationPolicy. The classmethods below construct a policy. Use passthrough() when selected hosts should receive the placeholder unchanged; the other three mirror the plain ViolationAction values.

ViolationPolicy.block()

Silently drop the request when the placeholder is sent to a disallowed host. The guest sees a connection reset. Equivalent to ViolationAction.BLOCK.

Returns

Policy with fallback = ViolationAction.BLOCK.

ViolationPolicy.block_and_log()

Drop the request and emit a warning log on the host side. This is the default. Equivalent to ViolationAction.BLOCK_AND_LOG.

Returns

Policy with fallback = ViolationAction.BLOCK_AND_LOG.

ViolationPolicy.block_and_terminate()

Drop the request, log an error, and shut down the entire sandbox. Equivalent to ViolationAction.BLOCK_AND_TERMINATE.

Returns

Policy with fallback = ViolationAction.BLOCK_AND_TERMINATE.

ViolationPolicy.passthrough()

Forward the placeholder unchanged to matching hosts instead of blocking. Passthrough hosts do not make a secret eligible for substitution; they only prevent blocking when the guest sends the placeholder to a matching host, so the request is forwarded with the placeholder intact. Hosts outside the passthrough set fall back to BLOCK_AND_LOG.

Parameters

hostsSequence[str]
Exact hosts that may receive the placeholder unchanged. Keyword-only. Default ().
host_patternsSequence[str]
Wildcard host patterns, e.g. “*.example.com”. Keyword-only. Default ().
all_hostsbool
Forward the placeholder unchanged to every host. Keyword-only. Default False.

Returns

Passthrough policy.

Types

SecretEntry

Returned by Secret.env()

A single secret entry, used in Sandbox.create(secrets=[...]). Construct it with Secret.env() rather than directly.

SecretInjection

Used by Secret.env() · SecretEntry.injection

Controls where in the HTTP request the secret value can be substituted.

ViolationAction

Used by Secret.env() · SecretEntry.on_violation

String enum (StrEnum) defining the action taken when a secret placeholder is sent to a disallowed host.

SecretViolationError

Subclass of MicrosandboxError

Raised when a secret placeholder was sent to a disallowed host. Carries code = "secret-violation".