Secret
Secret.env()
Example
Example
Sandbox.create(..., secrets=[...]).
Parameters
env_varstrEnvironment variable name. Must be non-empty and cannot contain
= or NUL; shell-identifier syntax is not required.valuestrThe real secret value. Never enters the guest VM. Keyword-only and required.
allow_hostsSequence[str]Hosts allowed to receive the real value (exact match). At least one exact or wildcard host is required. Default
().allow_host_patternsSequence[str]Wildcard host patterns, e.g.
“*.googleapis.com”. Default ().placeholderstr | NoneCustom placeholder string: non-empty, up to 1024 bytes, no NUL/CR/LF. Auto-generated as
$MSB_<env_var> when None. Default None.require_tlsboolOnly substitute on TLS-intercepted connections. Disable only if you know the traffic is safe. Default
True.Per-secret violation behavior. Default
ViolationAction.BLOCK_AND_LOG.injectionSecretInjection | NoneWhere in the HTTP request to substitute.
None uses SecretInjection() defaults. Default None.Returns
Secret entry for
Sandbox.create(secrets=[…]).ViolationPolicy
Used by Secret.env() · SecretEntry.on_violation
Secret violation behavior, including optional passthrough hosts. Construct it with the classmethods (block(), block_and_log(), block_and_terminate(), passthrough()) rather than setting fields directly.
policy.fallback
ViolationAction · Default: BLOCK_AND_LOG
Action for hosts not covered by the passthrough set
policy.passthrough_hosts
tuple[str, ...] · Default: ()
Exact hosts forwarded with the placeholder unchanged
policy.passthrough_host_patterns
tuple[str, ...] · Default: ()
Wildcard patterns forwarded with the placeholder unchanged
policy.passthrough_all_hosts
bool · Default: False
Forward the placeholder unchanged to every host
on_violation (per secret) and Network.on_secret_violation (sandbox-wide default) both accept a bare ViolationAction or a ViolationPolicy. The classmethods below construct a policy. Use passthrough() when selected hosts should receive the placeholder unchanged; the other three mirror the plain ViolationAction values.
ViolationPolicy.block()
ViolationAction.BLOCK.
Returns
Policy with
fallback = ViolationAction.BLOCK.ViolationPolicy.block_and_log()
ViolationAction.BLOCK_AND_LOG.
Returns
Policy with
fallback = ViolationAction.BLOCK_AND_LOG.ViolationPolicy.block_and_terminate()
ViolationAction.BLOCK_AND_TERMINATE.
Returns
Policy with
fallback = ViolationAction.BLOCK_AND_TERMINATE.ViolationPolicy.passthrough()
Example
Example
BLOCK_AND_LOG.
Parameters
hostsSequence[str]Exact hosts that may receive the placeholder unchanged. Keyword-only. Default
().host_patternsSequence[str]Wildcard host patterns, e.g.
“*.example.com”. Keyword-only. Default ().all_hostsboolForward the placeholder unchanged to every host. Keyword-only. Default
False.Returns
Passthrough policy.
Types
SecretEntry
Returned by Secret.env()
A single secret entry, used inSandbox.create(secrets=[...]). Construct it with Secret.env() rather than directly.
SecretInjection
Used by Secret.env() · SecretEntry.injection
Controls where in the HTTP request the secret value can be substituted.ViolationAction
Used by Secret.env() · SecretEntry.on_violation
String enum (StrEnum) defining the action taken when a secret placeholder is sent to a disallowed host.
SecretViolationError
Subclass of MicrosandboxError
code = "secret-violation".