Set the session's egress policy

Tells the VM whether its session's egress is restricted to an allowlist. The allowlist itself is enforced outside the VM, by Kernel's egress proxy, and is deliberately not sent here: the proxy is the only enforcement point, and a second copy of the destination list inside the VM could only drift from it.

The VM uses this to refuse requests that would route traffic around that proxy. Today that is the CDP command Target.createBrowserContext carrying proxyServer or proxyBypassList, which Playwright exposes as browser.newContext({ proxy }): with filtered: true the proxy answers it with a protocol error instead of forwarding it to Chromium.

Idempotent, and applied by the control plane both when the session is set up and whenever an allowlist is added to or removed from a running session. The policy is persisted, so it survives a restart of the instance API process; a request that cannot persist it returns 500 rather than reporting a policy that would be lost.

put/network/egress-policy

Request body

filteredboolean required

Whether the session's egress is restricted to an allowlist. When true, the VM refuses requests that would reach destinations without going through the proxy that enforces it.

Response

Egress policy applied

filteredboolean required

Whether the session's egress is restricted to an allowlist. When true, the VM refuses requests that would reach destinations without going through the proxy that enforces it.

Changes

Changed in 1 of the 65 revisions of this API.1