Guests stay on '-nic none' unless a profile opts in, and opting in does NOT mean internet: the NIC is user,restrict=on (no route out, no route to the host LAN) with one guestfwd to whatever command the overlay configures — a filtering proxy in practice. Keeps 'user code never gets a raw socket outside' true by construction. |
||
|---|---|---|
| .. | ||
| api | ||
| core | ||
| database | ||
| mcp | ||
| models | ||
| schemas | ||
| services | ||
| utils | ||
| __init__.py | ||
| main.py | ||