Skip to content

Access Profiles

Access profiles are preset firewall configurations that can be applied with a single click. They provide a simple interface for controlling the AI's internet access without manually managing individual rules.

Available Profiles

🔴 Locked

Maximum lockdown — DNS to gateway only.

Rule Protocol Port Destination
DNS to gateway (UDP) udp 53 192.168.10.1
DNS to gateway (TCP) tcp 53 192.168.10.1

The AI can perform DNS lookups (so you can see what it tries to reach), but cannot actually establish any connections. This is the default safe state.

🟠 Minimal

DNS + HTTPS only — packages, API calls.

Rule Protocol Port Destination
DNS to gateway (UDP) udp 53 192.168.10.1
DNS to gateway (TCP) tcp 53 192.168.10.1
HTTPS outbound tcp 443 any

The AI can browse websites, call APIs, and download packages. This covers most use cases for AI development.

🔵 Development

DNS + HTTP/S + SSH + Git.

Rule Protocol Port Destination
DNS to gateway (UDP) udp 53 192.168.10.1
DNS to gateway (TCP) tcp 53 192.168.10.1
HTTP outbound tcp 80 any
HTTPS outbound tcp 443 any
SSH outbound tcp 22 any
Git protocol tcp 9418 any

Full development access for coding tasks that require git operations and SSH connectivity.

🟢 Unrestricted

All egress traffic allowed — use with caution!

This profile disables the firewall entirely. The VM_EGRESS chain accepts all traffic. Only use when actively monitoring the AI.

Security Warning

Unrestricted mode gives the AI full internet access. It can reach any port on any host. Only enable this when you are actively watching what the AI does.

Profile Application Process

When a profile is applied:

  1. The current rules are completely replaced
  2. The firewall is enabled (except for "unrestricted" which disables it)
  3. The killswitch is deactivated
  4. Rules are immediately applied to iptables
  5. An audit event is logged with severity "warning" for unrestricted, "info" for others
  6. Configuration is persisted to disk

Detecting Current Level

The frontend detects the current access level by analyzing the active rules:

killswitch active → "killed"
firewall disabled → "unrestricted"
has SSH rule (port 22) → "development"
has HTTPS rule (port 443) → "minimal"
otherwise → "locked"

Custom Rules

Custom rules can be added alongside any profile. For example, after applying "Minimal", you could add a rule allowing SSH to a specific host:

{
  "description": "SSH to GitHub",
  "protocol": "tcp",
  "port": 22,
  "destination": "github.com"
}

The destination can be an IP address, CIDR range, or hostname.