Network and egress
By default, nothing gets out.
One namespace per microVM
Section titled “One namespace per microVM”A snapshot stores the name of the host’s TAP device. N copies of the same golden would all ask for the same TAP.
The fix: one network namespace per microVM. Inside it, the TAP is always tap0 and the guest always has the same IP. One snapshot works for all of them.
host │ netns kl-<id> │ microVM vh-<id> 172.30.a.b/30 ◄─veth─► vg-<id> 172.30.a.b+1 │ │ tap0 172.16.0.1/30 ├─ eth0 172.16.0.2Three egress modes
Section titled “Three egress modes”kling run -egress none # default: answers, starts nothingkling run -egress internet # internet, never private networkskling run -egress allowlist -allow api.github.com,pypi.orgallowlist fails closed: only the declared domains get out (DNS → ipset). An unknown value is an error, not the most permissive mode.
Checked from inside the guest
Section titled “Checked from inside the guest”RESULT 192.168.2.100: BLOCKED (Proxmox host)RESULT 192.168.2.1: BLOCKED (home router)RESULT 10.10.10.1: BLOCKED (WireGuard tunnel)RESULT 169.254.169.254: BLOCKED (cloud metadata)RESULT 1.1.1.1: REACHABLEEach machine is capped at 16 MiB/s of network and 128 MiB/s of disk.
In the repo: README: network · SECURITY.md