docs: clarify sandbox MCP policy scope - #25805
Conversation
MCP access guidance could imply that blocking a server prevents every connection from a sandbox. Clarify that MCP policy governs the Docker gateway path, while network policy governs direct outbound MCP connections.
✅ Deploy Preview for docsdocker ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
docker-agent
left a comment
There was a problem hiding this comment.
Assessment: 🟢 APPROVE
The changes correctly clarify the scope of MCP access policies (governing server registration and requests through the Docker Sandboxes MCP gateway) versus direct MCP connections (governed by network policy). The additions are concise, accurate, and consistent with the existing document tone and structure. No style violations, missing redirects, AI-isms, or content accuracy issues found.
docker-agent
left a comment
There was a problem hiding this comment.
Assessment: 🟢 APPROVE
This is a clean, well-scoped clarification. The new prose correctly distinguishes MCP gateway access policies from direct MCP connections subject to network policy. No vendored files, no redirects needed, no style violations, no broken Markdown.
docker-agent
left a comment
There was a problem hiding this comment.
Assessment: 🟢 APPROVE
This PR makes a focused, well-scoped clarification. The two changed files correctly explain that MCP access policies govern server registration and requests through the Docker Sandboxes MCP gateway, while direct MCP connections are subject to network access policy. The changes are accurate, consistent with each other, and match the existing documents' style and length. No issues found.
Summary
Clarify that MCP access policies govern server registration and requests through the Docker Sandboxes MCP gateway, while direct MCP connections remain subject to network policy.
@netlify /ai/sandboxes/governance/access-controls/mcp/
Preview
Generated by Codex