Where to configure it
Settings > Container & Network
Available policies
LLM providers onlyAllowlistFull access
Important behavior
- Network policy controls apply to containerized workspaces.
- Allowlist editing is active when policy is set to
Allowlist. - Allowlist entries are one per line.
Practical default policy
For most teams:- Start with
LLM providers only. - Move to
Allowlistwhen specific hosts are required. - Use
Full accessonly when the task truly needs it.
Allowlist tips
- Keep hostnames minimal and explicit.
- Remove temporary entries after one-off tasks.
- Track policy exceptions in team docs.