Print the live egress policy as an agent.yaml network block.
Synopsis
Print the deployed egress mode and api-managed destinations as a YAML snippet.
Merge egress_mode and egress into the existing network: mapping. Adding a second top-level network: key breaks the file, and the snippet does not fit a manifest that declares egress under sandboxes.*.network. The snippet names egress_mode, so the next deploy owns the destination list: live API destinations missing from the snippet stop applying.
Hosts that cannot be one agent.yaml rule (already declared in the file or from MCP, or agent and tool use different ports) go to stderr and YAML comments. Pasting the snippet and deploying drops them.
Examples:
agentengine egress export
agentengine egress export [flags]
Options
--base-url string Platform base URL --context string Named context to target (see 'agentengine context list') -h, --help help for export --org-id string Organization ID --project-id string Project ID --workspace string Monorepo: select a specific workspace by name (from root agent.yaml) --workspace-id string Workspace ID
Options inherited from parent commands
--log-file string override log file path --log-level string file log verbosity (error|warn|info|debug) (default "info") --no-log disable file logging -q, --quiet silence stderr below error -v, --verbose count raise stderr verbosity (-v info, -vv debug)
SEE ALSO
- agentengine egress - Show the deployed egress policy.