Containers, Agents - Secure credential injection and dynamic egress policies for Sandboxes
Outbound Workers for Sandboxes and Containers now support zero-trust credential injection, TLS interception, allow/deny lists, and dynamic per-instance egress policies. These features give platforms running agentic workloads full control over what leaves the sandbox, without exposing secrets to untrusted workloads, like user-generated code or coding agents. Credential injection Because outbound handlers run in the Workers runtime, outside the sandbox, they can hold secrets the sandbox never sees

