Skip to content

opencode sandbox policy: npm child-process CONNECT denied (ECONNRESET) and no Vertex AI / WIF egress #91

Description

@yvonnedevlinrh

Summary

The opencode network policy (in both sandboxes/base/policy.yaml and sandboxes/gemini/policy.yaml) has two egress gaps that break real-world OpenCode usage:

  1. npm installs fail with ECONNRESET. registry.npmjs.org is listed as an endpoint, but the npm binary is not in the policy's binaries: allowlist. When opencode spawns a background npm install (arborist), the connecting process is /usr/local/bin/npm (or /usr/bin/npm), not
    the allowlisted opencode/node binaries, so its CONNECT to registry.npmjs.org is denied.

  2. No Google / Vertex AI egress. The opencode policy has zero Google hosts, so running OpenCode against a google-vertex-* provider (Vertex AI, including Workload Identity Federation) cannot reach the requiredGoogle endpoints.

Environment

  • Base image: nvcr.io/nvidia/base/ubuntu:noble-20251013 (Ubuntu 24.04)
  • Node 22.22.1-1nodesource1, npm 11.11.0, opencode-ai@1.2.18 (global)
  • Sandbox invoked non-interactively: openshell sandbox exec -- sh -c <cmd>

Repro - npm ECONNRESET

  1. Start an opencode sandbox.
  2. In a repo whose deps aren't fully installed, trigger opencode's background dependency install (or run npm install directly).
  3. The CONNECT to registry.npmjs.org is denied → ECONNRESET.

Expected: npm reaches registry.npmjs.org (endpoint already allowlisted).
Actual: connection reset, because the npm binary isn't in the opencode policy's binaries: list.

Root cause: policy pairs are (binary, endpoint). registry.npmjs.org is a plain CONNECT tunnel (no tls: terminate), so this is not TLS-MITM - it is a binary allowlist gap. droid and ollama already ship dedicated npm policies; opencode never allowlists npm.

Repro - Vertex AI / WIF egress

  1. Configure opencode with a google-vertex-anthropic/* model.
  2. Run any request.
  3. Auth token exchange and inference fail: no route to sts.googleapis.com, oauth2.googleapis.com, or *-aiplatform.googleapis.com.

Note: the gemini policy ships the Google auth host set but uses service-account impersonation, so it lacks sts.googleapis.com.
GitHub-OIDC Workload Identity Federation additionally requires sts.googleapis.com:443.

Proposed fix

  1. Add /usr/local/bin/npm and /usr/bin/npm to the opencode policy's binaries: (or a shared dedicated npm policy as droid/ollama do).
  2. Add the Vertex AI + Google token hosts (mirroring gemini, plus sts.googleapis.com for WIF) to the opencode policy's endpoints:.

A PR applying (1) and (2) to the base and gemini policies will follow.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions