From 941ee7fdc0d6d2ca30fe381af7889bb47937f873 Mon Sep 17 00:00:00 2001 From: Thomas Gauvin Date: Wed, 23 Sep 2026 16:50:15 -0400 Subject: [PATCH] [Containers] Move outbound traffic under configuration --- public/__redirects | 3 ++- .../changelog/containers/2026-03-26-outbound-workers.mdx | 2 +- .../2026-04-13-sandbox-outbound-workers-tls-auth.mdx | 2 +- src/content/docs/containers/concepts/index.mdx | 2 +- .../containers/{guides => configuration}/outbound-traffic.mdx | 0 .../docs/containers/configuration/workers-connections.mdx | 4 ++-- src/content/docs/containers/faq.mdx | 2 +- src/content/docs/containers/reference/container-class.mdx | 4 ++-- .../diagrams/ai/enterprise-ai-vibe-coding-platform.mdx | 2 +- src/content/docs/sandbox/guides/outbound-traffic.mdx | 2 +- src/content/docs/sandbox/tutorials/openai-agents-api.mdx | 2 +- 11 files changed, 13 insertions(+), 12 deletions(-) rename src/content/docs/containers/{guides => configuration}/outbound-traffic.mdx (100%) diff --git a/public/__redirects b/public/__redirects index b3b8502f883..8c771b92197 100644 --- a/public/__redirects +++ b/public/__redirects @@ -656,7 +656,7 @@ # Containers IA rework: platform-details/ dissolved into core sections /containers/platform-details/architecture/ /containers/concepts/architecture/ 301 /containers/platform-details/placement/ /containers/concepts/placement/ 301 -/containers/platform-details/outbound-traffic/ /containers/guides/outbound-traffic/ 301 +/containers/platform-details/outbound-traffic/ /containers/configuration/outbound-traffic/ 301 /containers/platform-details/workers-connections/ /containers/configuration/workers-connections/ 301 /containers/platform-details/environment-variables/ /containers/configuration/environment-variables/ 301 /containers/platform-details/rollouts/ /containers/configuration/rollouts/ 301 @@ -666,6 +666,7 @@ /containers/platform-details/durable-object-methods/ /durable-objects/api/container/ 301 /containers/platform-details/ /containers/concepts/architecture/ 301 # Containers IA rework: Configuration section + Local Development to Guides + Wrangler pages to Reference +/containers/guides/outbound-traffic/ /containers/configuration/outbound-traffic/ 301 /containers/reference/local-dev/ /containers/guides/local-dev/ 301 /containers/reference/environment-variables/ /containers/configuration/environment-variables/ 301 /containers/reference/scaling-and-routing/ /containers/configuration/scaling-and-routing/ 301 diff --git a/src/content/changelog/containers/2026-03-26-outbound-workers.mdx b/src/content/changelog/containers/2026-03-26-outbound-workers.mdx index 80efb1f9b20..4d09b7a470f 100644 --- a/src/content/changelog/containers/2026-03-26-outbound-workers.mdx +++ b/src/content/changelog/containers/2026-03-26-outbound-workers.mdx @@ -78,4 +78,4 @@ This provides an easy way to associate state with any container instance, and in Upgrade to `@cloudflare/containers` version 0.2.0 or later, or `@cloudflare/sandbox` version 0.8.0 or later to use outbound Workers. -Refer to [Containers outbound traffic](/containers/guides/outbound-traffic/) and [Sandboxes outbound traffic](/sandbox/guides/outbound-traffic/) for more details and examples. +Refer to [Containers outbound traffic](/containers/configuration/outbound-traffic/) and [Sandboxes outbound traffic](/sandbox/guides/outbound-traffic/) for more details and examples. diff --git a/src/content/changelog/containers/2026-04-13-sandbox-outbound-workers-tls-auth.mdx b/src/content/changelog/containers/2026-04-13-sandbox-outbound-workers-tls-auth.mdx index f5fe931784a..7b563931f02 100644 --- a/src/content/changelog/containers/2026-04-13-sandbox-outbound-workers-tls-auth.mdx +++ b/src/content/changelog/containers/2026-04-13-sandbox-outbound-workers-tls-auth.mdx @@ -109,4 +109,4 @@ Handlers accept `params`, so you can customize behavior per instance without def Upgrade to `@cloudflare/containers@0.3.0` or `@cloudflare/sandbox@0.8.9` to use these features. -For more details, refer to [Sandbox outbound traffic](/sandbox/guides/outbound-traffic/) and [Container outbound traffic](/containers/guides/outbound-traffic/). +For more details, refer to [Sandbox outbound traffic](/sandbox/guides/outbound-traffic/) and [Container outbound traffic](/containers/configuration/outbound-traffic/). diff --git a/src/content/docs/containers/concepts/index.mdx b/src/content/docs/containers/concepts/index.mdx index 051a83f11d1..9a727955514 100644 --- a/src/content/docs/containers/concepts/index.mdx +++ b/src/content/docs/containers/concepts/index.mdx @@ -96,7 +96,7 @@ A Container can reach Cloudflare storage and external services through configure -For more information, refer to [Connect to Workers and bindings](/containers/configuration/workers-connections/) and [Outbound traffic](/containers/guides/outbound-traffic/). +For more information, refer to [Connect to Workers and bindings](/containers/configuration/workers-connections/) and [Outbound traffic](/containers/configuration/outbound-traffic/). ## Start building diff --git a/src/content/docs/containers/guides/outbound-traffic.mdx b/src/content/docs/containers/configuration/outbound-traffic.mdx similarity index 100% rename from src/content/docs/containers/guides/outbound-traffic.mdx rename to src/content/docs/containers/configuration/outbound-traffic.mdx diff --git a/src/content/docs/containers/configuration/workers-connections.mdx b/src/content/docs/containers/configuration/workers-connections.mdx index bd00691c72f..8cf45a36f38 100644 --- a/src/content/docs/containers/configuration/workers-connections.mdx +++ b/src/content/docs/containers/configuration/workers-connections.mdx @@ -8,7 +8,7 @@ products: - containers --- -Containers can access [Workers bindings](/workers/runtime-apis/bindings/) — KV, R2, D1, Durable Objects, and others — through [outbound handlers](/containers/guides/outbound-traffic/#define-outbound-handlers). An outbound handler intercepts HTTP requests from the container and runs inside the Workers runtime, where all of your configured bindings are available. +Containers can access [Workers bindings](/workers/runtime-apis/bindings/) — KV, R2, D1, Durable Objects, and others — through [outbound handlers](/containers/configuration/outbound-traffic/#define-outbound-handlers). An outbound handler intercepts HTTP requests from the container and runs inside the Workers runtime, where all of your configured bindings are available. The container makes a plain HTTP request to a virtual hostname (for example, `http://my.kv/some-key`), and the outbound handler resolves it using the bound resource. No SDK or client library is required inside the container. @@ -57,6 +57,6 @@ The `ctx` argument exposes `containerId`, which lets you interact with the conta ## Related resources -- [Handle outbound traffic](/containers/guides/outbound-traffic/) — Block, allow, and intercept all outbound HTTP from a container +- [Handle outbound traffic](/containers/configuration/outbound-traffic/) — Block, allow, and intercept all outbound HTTP from a container - [Environment variables and secrets](/containers/configuration/environment-variables/) — Configure secrets and environment variables - [Durable Object interface](/durable-objects/api/container/) — Full `ctx.container` API reference diff --git a/src/content/docs/containers/faq.mdx b/src/content/docs/containers/faq.mdx index 77b127711ec..982cdc3fe55 100644 --- a/src/content/docs/containers/faq.mdx +++ b/src/content/docs/containers/faq.mdx @@ -175,4 +175,4 @@ For a complete working example, see the [Docker-in-Docker Containers example](ht ## How do I allow or disallow egress from my container? -Refer to [Handle outbound traffic](/containers/guides/outbound-traffic/) for how to control outbound traffic and internet access. +Refer to [Handle outbound traffic](/containers/configuration/outbound-traffic/) for how to control outbound traffic and internet access. diff --git a/src/content/docs/containers/reference/container-class.mdx b/src/content/docs/containers/reference/container-class.mdx index b3a3c160245..1c32036aac7 100644 --- a/src/content/docs/containers/reference/container-class.mdx +++ b/src/content/docs/containers/reference/container-class.mdx @@ -102,7 +102,7 @@ Configure these as class fields on your subclass. They apply to every instance o `true`) — controls whether the container can make outbound HTTP requests. Set to `false` for sandboxed environments where you want to intercept or block all outbound traffic. For more information, refer to [Handle outbound - traffic](/containers/guides/outbound-traffic/). + traffic](/containers/configuration/outbound-traffic/). - **`pingEndpoint`** (`string`, default: `"ping"`) — the host and path the class uses to health-check the container @@ -719,7 +719,7 @@ export default { ``` -For more information, refer to [Handle outbound traffic](/containers/guides/outbound-traffic/). +For more information, refer to [Handle outbound traffic](/containers/configuration/outbound-traffic/). ## Utility functions diff --git a/src/content/docs/reference-architecture/diagrams/ai/enterprise-ai-vibe-coding-platform.mdx b/src/content/docs/reference-architecture/diagrams/ai/enterprise-ai-vibe-coding-platform.mdx index 52c4c03ea23..17b22409d26 100644 --- a/src/content/docs/reference-architecture/diagrams/ai/enterprise-ai-vibe-coding-platform.mdx +++ b/src/content/docs/reference-architecture/diagrams/ai/enterprise-ai-vibe-coding-platform.mdx @@ -54,7 +54,7 @@ With a local agent harness, developers use CLI-based tools like Cursor, Windsurf All LLM interactions are tracked and managed through [AI Gateway](/ai-gateway/), which provides provider routing, cost controls, prompt logging, and [DLP inspection](/cloudflare-one/data-loss-prevention/). [Cost tracking](/ai-gateway/observability/costs/) attributes usage to projects, teams, departments, and individual users. -All egress from the development environment is controlled at the platform level. For containers, an [outbound handler](/containers/guides/outbound-traffic/) intercepts HTTP traffic. For Dynamic Workers, [egress control](/dynamic-workers/usage/egress-control/) provides equivalent capabilities. Secrets required for downstream connectivity are stored in [Secrets Store](/secrets-store/) and injected by the outbound handler at the platform level. The sandboxed environment never has direct access to credentials. With this outbound handler, platform administrators can allow or deny specific origin destinations, reroute traffic, apply custom policies on outbound traffic, or connect to other Cloudflare resources through [bindings](/workers/runtime-apis/bindings/). For access to on-premises or internal systems, [Workers VPC](/workers-vpc/) establishes private connectivity without exposing those systems to the Internet. +All egress from the development environment is controlled at the platform level. For containers, an [outbound handler](/containers/configuration/outbound-traffic/) intercepts HTTP traffic. For Dynamic Workers, [egress control](/dynamic-workers/usage/egress-control/) provides equivalent capabilities. Secrets required for downstream connectivity are stored in [Secrets Store](/secrets-store/) and injected by the outbound handler at the platform level. The sandboxed environment never has direct access to credentials. With this outbound handler, platform administrators can allow or deny specific origin destinations, reroute traffic, apply custom policies on outbound traffic, or connect to other Cloudflare resources through [bindings](/workers/runtime-apis/bindings/). For access to on-premises or internal systems, [Workers VPC](/workers-vpc/) establishes private connectivity without exposing those systems to the Internet. Additional security controls can be layered into the development container through package version locking and organizational controls baked into the container image. If the harness uses MCP servers, [MCP portals](/cloudflare-one/access-controls/ai-controls/mcp-portals/) provide audit logging of tool invocations, permission management for tool access, and visibility into which tools agents use and what data they access. diff --git a/src/content/docs/sandbox/guides/outbound-traffic.mdx b/src/content/docs/sandbox/guides/outbound-traffic.mdx index e3da306c4a5..70b871df68a 100644 --- a/src/content/docs/sandbox/guides/outbound-traffic.mdx +++ b/src/content/docs/sandbox/guides/outbound-traffic.mdx @@ -289,6 +289,6 @@ Requests are evaluated in this order: ## Related resources - [Connect to Workers bindings](/sandbox/guides/workers-connections/) — Access KV, R2, Durable Objects, and other bindings from a sandbox -- [Handle outbound traffic (Containers)](/containers/guides/outbound-traffic/) — Container SDK API for outbound handlers +- [Handle outbound traffic (Containers)](/containers/configuration/outbound-traffic/) — Container SDK API for outbound handlers - [Sandbox options](/sandbox/configuration/sandbox-options/) — Configure sandbox behavior - [Environment variables](/sandbox/configuration/environment-variables/) — Configure secrets and environment variables diff --git a/src/content/docs/sandbox/tutorials/openai-agents-api.mdx b/src/content/docs/sandbox/tutorials/openai-agents-api.mdx index 386c89d2f8f..8e1b9d93195 100644 --- a/src/content/docs/sandbox/tutorials/openai-agents-api.mdx +++ b/src/content/docs/sandbox/tutorials/openai-agents-api.mdx @@ -353,7 +353,7 @@ Run `npm run deploy` from `openai/agents-api` to build and deploy the updated im The runnable example is intentionally minimal. Review these defaults before adapting it for production: - **Secrets:** The controller key, webhook secret, and `EXECUTOR_CLIENT_SECRET` remain Worker secrets. The restricted executor key is passed into the container as `CODEX_API_KEY`, where processes inside the container can read it. Refer to [Container environment variables and secrets](/containers/examples/env-vars-and-secrets/) for other ways to configure container instances. -- **Network access:** The example enables outbound Internet access so `codex exec-server` can reach OpenAI. Use [Container outbound traffic controls](/containers/platform-details/outbound-traffic/) to restrict destinations or inject credentials for other services. +- **Network access:** The example enables outbound Internet access so `codex exec-server` can reach OpenAI. Use [Container outbound traffic controls](/containers/configuration/outbound-traffic/) to restrict destinations or inject credentials for other services. - **Files:** `/workspace` uses ephemeral container storage. Use a [read-only R2 FUSE mount](/containers/examples/r2-fuse-mount/#mounting-buckets-as-read-only) when an agent needs durable source files that it should not modify. - **Worker access:** OpenAI must be able to reach `/webhook` without an interactive Access login. The Worker verifies OpenAI's webhook signature, and the manual cleanup endpoint requires `EXECUTOR_CLIENT_SECRET`. If you protect other routes with Cloudflare Access, use [path-specific policies](/cloudflare-one/access-controls/policies/app-paths/) that leave `/webhook` reachable.