Access Profiles¶
Access profiles are preset firewall configurations that can be applied with a single click. They provide a simple interface for controlling the AI's internet access without manually managing individual rules.
Available Profiles¶
🔴 Locked¶
Maximum lockdown — DNS to gateway only.
| Rule | Protocol | Port | Destination |
|---|---|---|---|
| DNS to gateway (UDP) | udp | 53 | 192.168.10.1 |
| DNS to gateway (TCP) | tcp | 53 | 192.168.10.1 |
The AI can perform DNS lookups (so you can see what it tries to reach), but cannot actually establish any connections. This is the default safe state.
🟠Minimal¶
DNS + HTTPS only — packages, API calls.
| Rule | Protocol | Port | Destination |
|---|---|---|---|
| DNS to gateway (UDP) | udp | 53 | 192.168.10.1 |
| DNS to gateway (TCP) | tcp | 53 | 192.168.10.1 |
| HTTPS outbound | tcp | 443 | any |
The AI can browse websites, call APIs, and download packages. This covers most use cases for AI development.
🔵 Development¶
DNS + HTTP/S + SSH + Git.
| Rule | Protocol | Port | Destination |
|---|---|---|---|
| DNS to gateway (UDP) | udp | 53 | 192.168.10.1 |
| DNS to gateway (TCP) | tcp | 53 | 192.168.10.1 |
| HTTP outbound | tcp | 80 | any |
| HTTPS outbound | tcp | 443 | any |
| SSH outbound | tcp | 22 | any |
| Git protocol | tcp | 9418 | any |
Full development access for coding tasks that require git operations and SSH connectivity.
🟢 Unrestricted¶
All egress traffic allowed — use with caution!
This profile disables the firewall entirely. The VM_EGRESS chain accepts all traffic. Only use when actively monitoring the AI.
Security Warning
Unrestricted mode gives the AI full internet access. It can reach any port on any host. Only enable this when you are actively watching what the AI does.
Profile Application Process¶
When a profile is applied:
- The current rules are completely replaced
- The firewall is enabled (except for "unrestricted" which disables it)
- The killswitch is deactivated
- Rules are immediately applied to iptables
- An audit event is logged with severity "warning" for unrestricted, "info" for others
- Configuration is persisted to disk
Detecting Current Level¶
The frontend detects the current access level by analyzing the active rules:
killswitch active → "killed"
firewall disabled → "unrestricted"
has SSH rule (port 22) → "development"
has HTTPS rule (port 443) → "minimal"
otherwise → "locked"
Custom Rules¶
Custom rules can be added alongside any profile. For example, after applying "Minimal", you could add a rule allowing SSH to a specific host:
The destination can be an IP address, CIDR range, or hostname.