For AI agents: a documentation index is available at https://www.mongodb.com/docs/llms.txt — markdown versions of all pages are available by appending .md to any URL path.
Docs Menu

agentengine egress

Show the deployed egress policy.

Show the egress policy deployed for a workspace.

Every workspace has a platform-managed base policy that allows DNS, in-namespace platform services, and any Atlas clusters linked with network.atlas_clusters. All other outbound traffic, including LLM APIs and third-party services, must be allow-listed explicitly. New workspaces start with both sandboxes in deny_all.

Modes apply per sandbox:

Mode
Description

deny_all

Only the base policy. User destinations do not apply.

allow_list

The base policy plus the listed destinations.

allow_all

Unrestricted external internet for that sandbox. Platform isolation (host, Kubernetes API server, instance metadata, private address ranges) still applies.

The agent sandbox runs your agent code. The tool sandbox executes tool calls, including MCP tools. Allow-list a host on each sandbox whose process connects to it.

Live writes are refused: egress save and egress clear fail locally and never call the platform. Change destinations with agentengine agent egress add, remove, or mode, then redeploy.

Examples:

agentengine egress agentengine egress --workspace my-workspace
agentengine egress [flags]
--base-url string Platform base URL
--context string Named context to target (see 'agentengine context list')
-h, --help help for egress
--org-id string Organization ID
--project-id string Project ID
--workspace string Monorepo: select a specific workspace by name (from root agent.yaml)
--workspace-id string Workspace ID
--log-file string override log file path
--log-level string file log verbosity (error|warn|info|debug) (default "info")
--no-log disable file logging
-q, --quiet silence stderr below error
-v, --verbose count raise stderr verbosity (-v info, -vv debug)
Rate this page