Skip to content

Network and egress

By default, nothing gets out.

A snapshot stores the name of the host’s TAP device. N copies of the same golden would all ask for the same TAP.

The fix: one network namespace per microVM. Inside it, the TAP is always tap0 and the guest always has the same IP. One snapshot works for all of them.

host │ netns kl-<id> │ microVM
vh-<id> 172.30.a.b/30 ◄─veth─► vg-<id> 172.30.a.b+1 │
│ tap0 172.16.0.1/30 ├─ eth0 172.16.0.2
Terminal window
kling run -egress none # default: answers, starts nothing
kling run -egress internet # internet, never private networks
kling run -egress allowlist -allow api.github.com,pypi.org

allowlist fails closed: only the declared domains get out (DNS → ipset). An unknown value is an error, not the most permissive mode.

RESULT 192.168.2.100: BLOCKED (Proxmox host)
RESULT 192.168.2.1: BLOCKED (home router)
RESULT 10.10.10.1: BLOCKED (WireGuard tunnel)
RESULT 169.254.169.254: BLOCKED (cloud metadata)
RESULT 1.1.1.1: REACHABLE

Each machine is capped at 16 MiB/s of network and 128 MiB/s of disk.