Repository navigation
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
## Summary The metro egress proxy is gaining per-session egress allowlists. When a destination isn't on the allowlist, the proxy answers with a branded **403** carrying `X-Kernel-Proxy-Error: network_policy_denied`. Other proxy-layer failures still return 502. Before this change, the CDP monitor only checked branded 502s, so a denial produced no `proxy_error` event. This PR: - treats 403 as a branded-response status alongside 502. Only those two statuses pay for the header decode; other responses still cost just the status compare. A website's own 403 without the header emits nothing. - adds `network_policy_denied` to the published `proxy_error` code enum, so the event carries the typed code instead of `unknown` with a `raw_code`. The spec descriptions now mention the 403. - adds `destination_route_unavailable` and `origin_response_incomplete` to the enum as well. The proxy already serves both as branded 502s, but the image reported them as `unknown` with a `raw_code`. - updates the cdpmonitor README, which still described `proxy_error` as 502-only, and notes that a CONNECT the proxy refuses outright, such as a denied CONNECT to a port other than 443, shows up only as `network_loading_failed` because Chromium doesn't expose the refusal. The 403 handling can ship before or after the proxy change: until the proxy sends these 403s, nothing changes for them. The two added codes take effect as soon as an image with this change ships. It does need to be in a released image before kernel/docs#657 is published, since that PR says denials show up as `proxy_error` events and drops the proxy errors page's note that `origin_response_incomplete` isn't reported. ## Validation - `cd server && go test ./lib/cdpmonitor/... ./lib/events/... ./lib/oapi/...` - `KERNEL_CDPMONITOR_CHROME_E2E=1 go test ./lib/cdpmonitor/ -run TestProxyErrorE2E` against real Chromium, with new cases for `network_policy_denied` (403), `destination_route_unavailable` and `origin_response_incomplete`. The last two come back as `unknown` with the previous generated enum. - The new unit test fails with the old 502-only gate. - `lib/oapi/oapi.go` was regenerated by running the `oapi-generate` steps directly. Unrelated `go mod tidy` changes to `go.sum` were left out. - Container e2e tests pass in CI (`test-server-e2e`). 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Changes network telemetry classification for 403 responses and expands the public proxy_error enum; mis-gating could false-positive on unrelated 403s, though the header gate limits that. > > **Overview** > Extends CDP monitor **`proxy_error`** detection so branded metro responses with **`X-Kernel-Proxy-Error`** are recognized on **403** as well as **502**, enabling typed telemetry when egress **network policy** blocks a destination (`network_policy_denied` with status 403). Plain site 403s without the header still do not emit **`proxy_error`**. > > The OpenAPI/`oapi` **`proxy_error` code enum** gains **`network_policy_denied`**, **`destination_route_unavailable`**, and **`origin_response_incomplete`**, with docs noting 403 vs 502 and that some CONNECT refusals remain **`network_loading_failed`** only. Unit and Chromium E2E tests cover the 403 gate and new codes; README event taxonomy is updated accordingly. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 493f2d3. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: meliaj <17581886+meliaj@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Add a page for network.allowed_hosts: creating a browser with an allowlist, the entry rules, what a blocked request returns, changing or removing the list with update(), keeping it away from the agent, and the limitations. List network_policy_denied and its 403 on the proxy errors page, and narrow the private networking note now that allowed_hosts can change after creation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Updating the allowlist: new requests are refused within seconds and open connections close within about 30 seconds, or up to 10 minutes during a Kernel deploy. - The WebRtcIPHandling and WebRtcIPHandlingUrl Chrome policies are rejected with an allowlist. - Public suffix rejections include provider domains such as *.cloudfront.net. - Limitations list what can leave the VM without the egress proxy: VM processes, CDP contexts with their own proxy, extensions with the proxy permission, and DNS lookups Chromium makes itself. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Blocked connections to ports other than 443 get a bare 403 that Chromium doesn't expose, so they show up as network_loading_failed, not proxy_error. The browser image release this page waits for reports origin_response_incomplete with its own code, so the proxy errors page no longer needs to say it isn't reported. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d one An allowlist is now set when the browser is created. update() can replace or remove it, but adding one to a browser created without it returns 400 not_supported, and one removed with null can't be added back.
59fa63a to
1c93ee2
Compare
|
This is great, can we also add to the appropriate place under "Security and Trust"? This is a differentiating feature and is strong evidence for our positioning that Kernel is the most secure browser for agent tasks. Something that enterprise companies always ask about. Maybe we add here? |
|
Folded in your suggestions. Is there any positioning language you want to add to the intro? |
AnnaXWang
left a comment
There was a problem hiding this comment.
This looks good to me for first release! I may iterate with solutions eng + marketing in a future rev but non-blocking
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit dba4bc4. Configure here.
|
|
||
| </CodeGroup> | ||
|
|
||
| A pool update replaces the entire `network` object, unlike a browser update. Omit `network` to leave it unchanged. If you provide it, include every network setting you want to keep, including `private_hosts` and `proxy_routes`. Omitting `allowed_hosts` from that replacement removes the pool's allowlist; `network: {}` clears the entire network configuration. An empty allowlist (`[]`) is invalid. You can add an allowlist to a pool that doesn't have one because its unfiltered browsers are replaced rather than given a list in place. |
There was a problem hiding this comment.
Pool network rules packed together
Low Severity
Several independent pool network update rules sit in one paragraph: whole-object replacement, omit-versus-replace behavior, clearing via network: {}, rejecting [], and adding an allowlist to a pool. Readers can miss that omitting allowed_hosts from a replacement removes the list.
Triggered by learned rule: Use bullet lists when covering multiple distinct points in guides
Reviewed by Cursor Bugbot for commit dba4bc4. Configure here.
hiroTamada
left a comment
There was a problem hiding this comment.
Should we wait public GA?


summary
validation
mint validate,mint broken-links, json parsing, andgit diff --checkpassed.mint format.mint dev: allowlist, pool, private-networking, shared responsibility, and security practices pages returned 200; new sections and anchors rendered.release
keep draft pending technical review and explicit launch authorization. don't merge until browser pool allowlist support is released. no changelog or ga changes.
Note
Low Risk
Documentation-only changes with no runtime or API implementation in this diff.
Overview
Adds a new Egress Allowlists guide under Configure → Proxies and wires it into the docs site navigation.
The page documents
network.allowed_hosts: create/update/remove semantics (including replacement-only PATCH and pool whole-objectnetworkupdates), entry validation, blocked-destination behavior (403/network_policy_denied), CAPTCHA provider hosts, CDP proxy-context refusal, and proxy-only enforcement limits.Related pages are updated so browser pools describe allowlist restore-on-reuse and automatic idle replacement when the pool list changes; proxy errors add
network_policy_deniedand clarify incompleteproxy_errortelemetry for CORS/ORB; private networking cross-links differing pool update rules; security and the shared responsibility model frame agent egress restriction as a shared control.Reviewed by Cursor Bugbot for commit dba4bc4. Bugbot is set up for automated code reviews on this repo. Configure here.