Commands, package names, and image names on this page come from the open-source project that Mibyan Desktop is built on, and can differ from the Mibyan Desktop installer. For the supported Mibyan install and update path, see Install and update.
network_mode: host gives the
agent process unrestricted outbound network access. This guide shows how to
segment traffic so the agent core can only reach the services it needs, while
blocking arbitrary outbound connections.
This is primarily a defense against prompt injection attacks that attempt to
exfiltrate data via curl, wget, or raw HTTP from tool-generated shell
commands.
Threat Model
The Mibyan SECURITY.md §2 defines the trust model. The terminal backend is the primary execution boundary. However, when running withnetwork_mode: host, any command the agent executes can reach any endpoint on
the network, including external ones.
Network egress isolation adds a second layer: even if a malicious command
executes inside the container, it cannot reach endpoints outside the
explicitly allowlisted set.
Architecture
internal— no default route, no internet access. The agent, dashboard, and gateway run here.egress— has internet access. Only services that need to reach external APIs are attached to this network.
Compose Configuration
Override the defaultdocker-compose.yml with a
docker-compose.override.yml:
With an Egress Proxy (Recommended)
For tighter control, route all outbound traffic through an HTTP proxy with an explicit allowlist:config/squid-allowlist.conf:
Validating the Setup
After bringing up the stack, verify isolation:Limitations
-
DNS resolution: The
internalnetwork can still resolve external DNS names unless you also run a local DNS resolver that blocks external queries. For most threat models this is acceptable since DNS resolution alone does not exfiltrate meaningful data. - Not a substitute for sandbox backends: This guide isolates the agent container’s network. If you use the default local terminal backend, tool commands execute inside the same container. For stronger isolation, combine network segmentation with a sandboxed terminal backend (Docker, Modal, Daytona).
- Platform adapters need egress: The gateway service needs outbound access to reach messaging platform APIs. If you add new platform adapters, add their API endpoints to the proxy allowlist.
Related
- SECURITY.md — Mibyan trust model and vulnerability reporting
- Docker — running Mibyan in a container
- Egress proxy — credential-injection firewall for the sandbox
- docker-compose.yml — default compose configuration

