hey simon,
smol machines actually support exactly those things across macs,linux, windows btw: https://github.com/smol-machines/smolvm/blob/main/AGENTS.md#...
here's a snippet of how it looks like to configure that:
[network]
allow_hosts = ["api.github.com"] # hostname, also allows its subdomains
allow_host_patterns = ["example.com", "*.npmjs.org"] # exact names, or *. for subdomains only
allow_cidrs = ["10.0.0.0/8", "1.1.1.1"] # IP ranges or single IPs
[[network.credentials]]
name = "github"
environment_variable = "GITHUB_TOKEN"how does it do it?
proxy in the middle (but cert pinning problems)
or DNS filtering? (but agent could have "memorized" stable IP)
+1 on smolvm! I provision a smolvm per job in preloop, a local/self-hosted github actions( https://github.com/preloopdev/preloop). iirc there was also some work to add a deny-cidr option as well which would give you more flexibility. But the egress filter captures most of what you need so it works great nonetheless.