Skip to content

add port security policy to the exposed port#51

Open
edouardb wants to merge 4 commits into
mainfrom
feat/port-security-policy
Open

add port security policy to the exposed port#51
edouardb wants to merge 4 commits into
mainfrom
feat/port-security-policy

Conversation

@edouardb

Copy link
Copy Markdown
Member

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds support for applying access-control security policies to the sandbox’s user-facing exposed port (route on port 3031), exposing the feature via the Sandbox.create()/AsyncSandbox.create() APIs and providing examples.

Changes:

  • Introduces ApiKey and BasicAuth policy helpers and maps them to SecurityPolicies on the 3031 route.
  • Extends sandbox creation to accept exposed_port_security_policy and applies it when default routes are generated.
  • Adds sync/async examples demonstrating no-auth, API-key, and Basic Auth access control.

Reviewed changes

Copilot reviewed 5 out of 6 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
uv.lock Updates the lockfile; also introduces a new optional extra and packages (socks, pysocks, socksio).
koyeb/sandbox/utils.py Adds policy dataclasses + builder, threads policy into generated routes and deployment definition.
koyeb/sandbox/sandbox.py Adds exposed_port_security_policy parameter to sync/async sandbox creation + updates docstrings/examples.
koyeb/sandbox/__init__.py Exports ApiKey and BasicAuth from koyeb.sandbox.
examples/21_port_security_policy.py New sync example validating behavior for public/API-key/basic-auth.
examples/21_port_security_policy_async.py New async example validating behavior for public/API-key/basic-auth.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread koyeb/sandbox/utils.py
Comment thread koyeb/sandbox/sandbox.py
Comment thread examples/21_port_security_policy.py
Comment thread koyeb/sandbox/__init__.py Outdated
Comment thread koyeb/sandbox/utils.py
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@edouardb

Copy link
Copy Markdown
Member Author

@copilot resolve the merge conflicts in this pull request

Copilot AI commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Merge conflicts have been resolved in this commit. The three conflicting files were:

  • koyeb/sandbox/__init__.py: Combined ApiKey/BasicAuth imports with the Snapshot/EgressPolicyError imports from main.
  • koyeb/sandbox/sandbox.py: Merged all three conflict blocks — docstring examples (kept both security-policy and snapshot examples), sync _create_sync (kept conditional secret generation and exposed_port_security_policy in create_deployment_definition), and async _create_async (same approach, also updated snapshot branches to use exposed_port_security_policy instead of an explicit pre-built routes variable).
  • uv.lock: Accepted the [options] block added by main.

All 29 existing tests continue to pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants