Allowed Hosts¶
Allowed hosts decide which servers an agent can reach directly. The agent reaches only those hosts and the AgentZ services it needs. You set them in the Allowed hosts step of the sandbox wizard. Open the wizard as in Sandbox packages.
Allowed Hosts Control Direct Network Access¶
The agent can reach only the hosts you list, plus AgentZ's own services. In the Allowed hosts step, type a value in Host and select Add. The host appears as a button. Click it to remove it.
| Format | Example | Matches |
|---|---|---|
| Hostname | api.github.com | That host only |
| One-label wildcard | *.example.com | One subdomain label |
| Any-depth wildcard | **.example.com | Subdomains at any depth |
| CIDR range | 10.0.0.0/24 | An IPv4 or IPv6 range |
Warning
A sandbox rejects a bare IP address such as 203.0.113.5. The error reads "Use a hostname, *.hostname, **.hostname, or CIDR range". Enter a single address as a CIDR range, for example 203.0.113.5/32.
AgentZ lowercases each host and removes duplicates. A host holds up to 253 characters.
LLM Traffic Needs No Allowed Host¶
Model calls go through the AgentZ inference gateway. Do not add your model provider's host. See Inference providers.
Auto-Accept Adds Secret Hosts to the Sandbox¶
Open your account menu, select Preferences, and turn on Auto-accept allowed host suggestions. It is off by default.
When you then create a secret, AgentZ adds the secret hosts to the sandbox of that agent. This update restarts every agent that uses the sandbox. AgentZ leaves an organization sandbox unchanged and shows a warning. See Secrets.