Skip to content

docs: clarify sandbox MCP policy scope - #25805

Open
dvdksn wants to merge 1 commit into
docker:mainfrom
dvdksn:codex/clarify-sandbox-mcp-policy
Open

docs: clarify sandbox MCP policy scope#25805
dvdksn wants to merge 1 commit into
docker:mainfrom
dvdksn:codex/clarify-sandbox-mcp-policy

Conversation

@dvdksn

@dvdksn dvdksn commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Summary

Clarify that MCP access policies govern server registration and requests through the Docker Sandboxes MCP gateway, while direct MCP connections remain subject to network policy.

@netlify /ai/sandboxes/governance/access-controls/mcp/

Preview

Generated by Codex

MCP access guidance could imply that blocking a server prevents every connection from a sandbox. Clarify that MCP policy governs the Docker gateway path, while network policy governs direct outbound MCP connections.
@netlify

netlify Bot commented Aug 12, 2026

Copy link
Copy Markdown

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit bf83e83
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6a7c2f6a05c3c10008b6e5bb
😎 Deploy Preview https://deploy-preview-25805--docsdocker.netlify.app/ai/sandboxes/governance/access-controls/mcp/
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

The changes correctly clarify the scope of MCP access policies (governing server registration and requests through the Docker Sandboxes MCP gateway) versus direct MCP connections (governed by network policy). The additions are concise, accurate, and consistent with the existing document tone and structure. No style violations, missing redirects, AI-isms, or content accuracy issues found.

@dvdksn
dvdksn marked this pull request as ready for review August 12, 2026 08:34
@dvdksn
dvdksn requested a review from craig-osterhout August 12, 2026 08:34

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

This is a clean, well-scoped clarification. The new prose correctly distinguishes MCP gateway access policies from direct MCP connections subject to network policy. No vendored files, no redirects needed, no style violations, no broken Markdown.

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

This PR makes a focused, well-scoped clarification. The two changed files correctly explain that MCP access policies govern server registration and requests through the Docker Sandboxes MCP gateway, while direct MCP connections are subject to network access policy. The changes are accurate, consistent with each other, and match the existing documents' style and length. No issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants