Add destinations to agent.yaml without touching existing ones.
Synopsis
Add one or more egress destinations to agent.yaml.
When the target sandbox has no mode or is deny_all, add sets it to allow_list. A sandbox on allow_all is left alone: destinations do not apply there, so run agentengine agent egress mode allow_list first. Adding a host already listed with different ports fails; remove it first.
Each argument is FQDN:PORT, FQDN:PORT,PORT,…, or a full URL. Omitting the port or using FQDN:* allows all ports. For a URL the host is extracted and the scheme’s standard port (https 443, ssh 22) is used when the URL names no explicit port; that inference is reported as a note. URLs carrying credentials and schemes with no known port are rejected.
The change takes effect on the next deploy. agentengine egress still shows the live workspace until then.
Examples:
agentengine agent egress add api.openai.com:443 # Allow MongoDB for the tool sandbox only agentengine agent egress add --component tool '\*.mongodb.net:443,27017'
agentengine agent egress add FQDN:PORT[,PORT...] [FQDN:PORT...] [flags]
Options
--component string Target a single sandbox: agent or tool. Omit to apply to both. -h, --help help for add --workspace string Monorepo: select a specific workspace by name (from root agent.yaml)
Options inherited from parent commands
--log-file string override log file path --log-level string file log verbosity (error|warn|info|debug) (default "info") --no-log disable file logging -q, --quiet silence stderr below error -v, --verbose count raise stderr verbosity (-v info, -vv debug)
SEE ALSO
- agentengine agent egress - Edit the egress allow-list in agent.yaml.