apple / apple/container

[Request]: Option to prevent host access on internal networks

Open
#1,320 6 comments 8 reactions 0 assignees View on GitHub
Dominant language
Swift
Stars
49.9k
Forks
1.8k
Avg merge
1d 20h
Merged PRs (30d)
22

Description

### Feature or enhancement request details

On `--internal` networks, the host gateway IP (e.g. `192.168.128.1`) is reachable from containers. Any host service bound to `0.0.0.0` is accessible from inside the VM. This is a concern for security-sensitive use cases like sandboxing AI coding agents, where if the agent runs as root inside the VM then it should not be able to reach the host.

### Current behavior:

- `container network create --internal` creates a network with no internet access
- The host gateway is still present on the subnet and reachable from containers
- macOS `pf` firewall rules don't seem to filter vmnet-bridged traffic
- Guest-side iptables works but is bypassable by a root process inside the VM

### Requested behavior:

A way to create a network where the host has no presence on the subnet, i.e. containers can communicate with each other but cannot reach the host. This would need to be enforced at the vmnet/hypervisor level so that it can't be bypassed from inside the VM.

### Use case:

Running autonomous AI agents (e.g. Claude Code with `--dangerously-skip-permissions`) in isolated VMs. The dual-homed proxy approach from discussion #1170 handles internet allowlisting well, but the agent VM can bypass the proxy to reach host services directly via the gateway IP. Related discussion: #719.

### Code of Conduct

- [x] I agree to follow this project's Code of Conduct

Contributor guide

Open the contributing guide

Research direction

Start with the `container network create --internal` path and the vmnet/hypervisor networking behavior described in the issue; review discussions #1170 and #719 for related constraints. Done means an internal network still permits container-to-container communication while preventing containers from reaching the host gateway, including when the guest process has root access.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos, swift
Domain
networking, operating-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.