Skip to main content
Commands, package names, and image names on this page come from the open-source project that Mibyan Desktop is built on, and can differ from the Mibyan Desktop installer. For the supported Mibyan install and update path, see Install and update.
When running Mibyan inside Docker, the default network_mode: host gives the agent process unrestricted outbound network access. This guide shows how to segment traffic so the agent core can only reach the services it needs, while blocking arbitrary outbound connections. This is primarily a defense against prompt injection attacks that attempt to exfiltrate data via curl, wget, or raw HTTP from tool-generated shell commands.

Threat Model

The Mibyan SECURITY.md §2 defines the trust model. The terminal backend is the primary execution boundary. However, when running with network_mode: host, any command the agent executes can reach any endpoint on the network, including external ones. Network egress isolation adds a second layer: even if a malicious command executes inside the container, it cannot reach endpoints outside the explicitly allowlisted set.

Architecture

Two Docker networks:
  • internal — no default route, no internet access. The agent, dashboard, and gateway run here.
  • egress — has internet access. Only services that need to reach external APIs are attached to this network.
The gateway service is dual-homed (attached to both networks) so it can receive inbound messages from Telegram/Slack/etc. and forward them to the agent on the internal network.

Compose Configuration

Override the default docker-compose.yml with a docker-compose.override.yml:
For tighter control, route all outbound traffic through an HTTP proxy with an explicit allowlist:
Example config/squid-allowlist.conf:
Adjust the allowlist to match your LLM provider and messaging platform.

Validating the Setup

After bringing up the stack, verify isolation:

Limitations

  • DNS resolution: The internal network can still resolve external DNS names unless you also run a local DNS resolver that blocks external queries. For most threat models this is acceptable since DNS resolution alone does not exfiltrate meaningful data.
  • Not a substitute for sandbox backends: This guide isolates the agent container’s network. If you use the default local terminal backend, tool commands execute inside the same container. For stronger isolation, combine network segmentation with a sandboxed terminal backend (Docker, Modal, Daytona).
  • Platform adapters need egress: The gateway service needs outbound access to reach messaging platform APIs. If you add new platform adapters, add their API endpoints to the proxy allowlist.