Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion public/__redirects
Original file line number Diff line number Diff line change
Expand Up @@ -656,7 +656,7 @@
# Containers IA rework: platform-details/ dissolved into core sections
/containers/platform-details/architecture/ /containers/concepts/architecture/ 301
/containers/platform-details/placement/ /containers/concepts/placement/ 301
/containers/platform-details/outbound-traffic/ /containers/guides/outbound-traffic/ 301
/containers/platform-details/outbound-traffic/ /containers/configuration/outbound-traffic/ 301
/containers/platform-details/workers-connections/ /containers/configuration/workers-connections/ 301
/containers/platform-details/environment-variables/ /containers/configuration/environment-variables/ 301
/containers/platform-details/rollouts/ /containers/configuration/rollouts/ 301
Expand All @@ -666,6 +666,7 @@
/containers/platform-details/durable-object-methods/ /durable-objects/api/container/ 301
/containers/platform-details/ /containers/concepts/architecture/ 301
# Containers IA rework: Configuration section + Local Development to Guides + Wrangler pages to Reference
/containers/guides/outbound-traffic/ /containers/configuration/outbound-traffic/ 301
/containers/reference/local-dev/ /containers/guides/local-dev/ 301
/containers/reference/environment-variables/ /containers/configuration/environment-variables/ 301
/containers/reference/scaling-and-routing/ /containers/configuration/scaling-and-routing/ 301
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -78,4 +78,4 @@ This provides an easy way to associate state with any container instance, and in

Upgrade to `@cloudflare/containers` version 0.2.0 or later, or `@cloudflare/sandbox` version 0.8.0 or later to use outbound Workers.

Refer to [Containers outbound traffic](/containers/guides/outbound-traffic/) and [Sandboxes outbound traffic](/sandbox/guides/outbound-traffic/) for more details and examples.
Refer to [Containers outbound traffic](/containers/configuration/outbound-traffic/) and [Sandboxes outbound traffic](/sandbox/guides/outbound-traffic/) for more details and examples.
Original file line number Diff line number Diff line change
Expand Up @@ -109,4 +109,4 @@ Handlers accept `params`, so you can customize behavior per instance without def

Upgrade to `@cloudflare/containers@0.3.0` or `@cloudflare/sandbox@0.8.9` to use these features.

For more details, refer to [Sandbox outbound traffic](/sandbox/guides/outbound-traffic/) and [Container outbound traffic](/containers/guides/outbound-traffic/).
For more details, refer to [Sandbox outbound traffic](/sandbox/guides/outbound-traffic/) and [Container outbound traffic](/containers/configuration/outbound-traffic/).
2 changes: 1 addition & 1 deletion src/content/docs/containers/concepts/index.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ A Container can reach Cloudflare storage and external services through configure

</ContainerConnectivity>

For more information, refer to [Connect to Workers and bindings](/containers/configuration/workers-connections/) and [Outbound traffic](/containers/guides/outbound-traffic/).
For more information, refer to [Connect to Workers and bindings](/containers/configuration/workers-connections/) and [Outbound traffic](/containers/configuration/outbound-traffic/).

## Start building

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ products:
- containers
---

Containers can access [Workers bindings](/workers/runtime-apis/bindings/) — KV, R2, D1, Durable Objects, and others — through [outbound handlers](/containers/guides/outbound-traffic/#define-outbound-handlers). An outbound handler intercepts HTTP requests from the container and runs inside the Workers runtime, where all of your configured bindings are available.
Containers can access [Workers bindings](/workers/runtime-apis/bindings/) — KV, R2, D1, Durable Objects, and others — through [outbound handlers](/containers/configuration/outbound-traffic/#define-outbound-handlers). An outbound handler intercepts HTTP requests from the container and runs inside the Workers runtime, where all of your configured bindings are available.

The container makes a plain HTTP request to a virtual hostname (for example, `http://my.kv/some-key`), and the outbound handler resolves it using the bound resource. No SDK or client library is required inside the container.

Expand Down Expand Up @@ -57,6 +57,6 @@ The `ctx` argument exposes `containerId`, which lets you interact with the conta

## Related resources

- [Handle outbound traffic](/containers/guides/outbound-traffic/) — Block, allow, and intercept all outbound HTTP from a container
- [Handle outbound traffic](/containers/configuration/outbound-traffic/) — Block, allow, and intercept all outbound HTTP from a container
- [Environment variables and secrets](/containers/configuration/environment-variables/) — Configure secrets and environment variables
- [Durable Object interface](/durable-objects/api/container/) — Full `ctx.container` API reference
2 changes: 1 addition & 1 deletion src/content/docs/containers/faq.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -175,4 +175,4 @@ For a complete working example, see the [Docker-in-Docker Containers example](ht

## How do I allow or disallow egress from my container?

Refer to [Handle outbound traffic](/containers/guides/outbound-traffic/) for how to control outbound traffic and internet access.
Refer to [Handle outbound traffic](/containers/configuration/outbound-traffic/) for how to control outbound traffic and internet access.
4 changes: 2 additions & 2 deletions src/content/docs/containers/reference/container-class.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,7 @@ Configure these as class fields on your subclass. They apply to every instance o
`true`) — controls whether the container can make outbound HTTP requests. Set
to `false` for sandboxed environments where you want to intercept or block all
outbound traffic. For more information, refer to [Handle outbound
traffic](/containers/guides/outbound-traffic/).
traffic](/containers/configuration/outbound-traffic/).

- <span id="pingendpoint"></span>**`pingEndpoint`** (`string`, default:
`"ping"`) — the host and path the class uses to health-check the container
Expand Down Expand Up @@ -719,7 +719,7 @@ export default {
```
</TypeScriptExample>

For more information, refer to [Handle outbound traffic](/containers/guides/outbound-traffic/).
For more information, refer to [Handle outbound traffic](/containers/configuration/outbound-traffic/).

## Utility functions

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ With a local agent harness, developers use CLI-based tools like Cursor, Windsurf

All LLM interactions are tracked and managed through [AI Gateway](/ai-gateway/), which provides provider routing, cost controls, prompt logging, and [DLP inspection](/cloudflare-one/data-loss-prevention/). [Cost tracking](/ai-gateway/observability/costs/) attributes usage to projects, teams, departments, and individual users.

All egress from the development environment is controlled at the platform level. For containers, an [outbound handler](/containers/guides/outbound-traffic/) intercepts HTTP traffic. For Dynamic Workers, [egress control](/dynamic-workers/usage/egress-control/) provides equivalent capabilities. Secrets required for downstream connectivity are stored in [Secrets Store](/secrets-store/) and injected by the outbound handler at the platform level. The sandboxed environment never has direct access to credentials. With this outbound handler, platform administrators can allow or deny specific origin destinations, reroute traffic, apply custom policies on outbound traffic, or connect to other Cloudflare resources through [bindings](/workers/runtime-apis/bindings/). For access to on-premises or internal systems, [Workers VPC](/workers-vpc/) establishes private connectivity without exposing those systems to the Internet.
All egress from the development environment is controlled at the platform level. For containers, an [outbound handler](/containers/configuration/outbound-traffic/) intercepts HTTP traffic. For Dynamic Workers, [egress control](/dynamic-workers/usage/egress-control/) provides equivalent capabilities. Secrets required for downstream connectivity are stored in [Secrets Store](/secrets-store/) and injected by the outbound handler at the platform level. The sandboxed environment never has direct access to credentials. With this outbound handler, platform administrators can allow or deny specific origin destinations, reroute traffic, apply custom policies on outbound traffic, or connect to other Cloudflare resources through [bindings](/workers/runtime-apis/bindings/). For access to on-premises or internal systems, [Workers VPC](/workers-vpc/) establishes private connectivity without exposing those systems to the Internet.

Additional security controls can be layered into the development container through package version locking and organizational controls baked into the container image. If the harness uses MCP servers, [MCP portals](/cloudflare-one/access-controls/ai-controls/mcp-portals/) provide audit logging of tool invocations, permission management for tool access, and visibility into which tools agents use and what data they access.

Expand Down
2 changes: 1 addition & 1 deletion src/content/docs/sandbox/guides/outbound-traffic.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -289,6 +289,6 @@ Requests are evaluated in this order:
## Related resources

- [Connect to Workers bindings](/sandbox/guides/workers-connections/) — Access KV, R2, Durable Objects, and other bindings from a sandbox
- [Handle outbound traffic (Containers)](/containers/guides/outbound-traffic/) — Container SDK API for outbound handlers
- [Handle outbound traffic (Containers)](/containers/configuration/outbound-traffic/) — Container SDK API for outbound handlers
- [Sandbox options](/sandbox/configuration/sandbox-options/) — Configure sandbox behavior
- [Environment variables](/sandbox/configuration/environment-variables/) — Configure secrets and environment variables
2 changes: 1 addition & 1 deletion src/content/docs/sandbox/tutorials/openai-agents-api.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -353,7 +353,7 @@ Run `npm run deploy` from `openai/agents-api` to build and deploy the updated im
The runnable example is intentionally minimal. Review these defaults before adapting it for production:

- **Secrets:** The controller key, webhook secret, and `EXECUTOR_CLIENT_SECRET` remain Worker secrets. The restricted executor key is passed into the container as `CODEX_API_KEY`, where processes inside the container can read it. Refer to [Container environment variables and secrets](/containers/examples/env-vars-and-secrets/) for other ways to configure container instances.
- **Network access:** The example enables outbound Internet access so `codex exec-server` can reach OpenAI. Use [Container outbound traffic controls](/containers/platform-details/outbound-traffic/) to restrict destinations or inject credentials for other services.
- **Network access:** The example enables outbound Internet access so `codex exec-server` can reach OpenAI. Use [Container outbound traffic controls](/containers/configuration/outbound-traffic/) to restrict destinations or inject credentials for other services.
- **Files:** `/workspace` uses ephemeral container storage. Use a [read-only R2 FUSE mount](/containers/examples/r2-fuse-mount/#mounting-buckets-as-read-only) when an agent needs durable source files that it should not modify.
- **Worker access:** OpenAI must be able to reach `/webhook` without an interactive Access login. The Worker verifies OpenAI's webhook signature, and the manual cleanup endpoint requires `EXECUTOR_CLIENT_SECRET`. If you protect other routes with Cloudflare Access, use [path-specific policies](/cloudflare-one/access-controls/policies/app-paths/) that leave `/webhook` reachable.

Expand Down
Loading