What you will build
A network-path worksheet and a loopback-only development-server demonstration. You will diagnose by direction: outbound guest traffic, inbound host-to-guest traffic, or guest-to-host service access.
- Guest client or server
- DNS and proxy path
- Explicit port mapping
- Host browser or service
Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.
Read the mechanism
localhost means the loopback interface of the environment where a process runs. A browser on your host and a process inside the sandbox do not share the same loopback interface. Opening host port 8080 does not automatically reach a guest server on port 8080.
Outbound TCP uses host-side proxy paths governed by network policy. HTTP/HTTPS and generic TCP do not have identical inspection features. DNS resolution, policy authorization, connection establishment and application response are separate stages. A DNS answer is not proof that the destination is allowed.
For an inbound development server, publish a guest port to a host address. Keep teaching servers on 127.0.0.1 at the host boundary. Binding the server to all interfaces inside the guest may be needed for forwarding; that is distinct from exposing the host listener on the LAN.
Worked lab · publish one service
Use a dedicated mountless shell sandbox. The example assumes the template has Python 3; verify that before starting and otherwise use an already installed equivalent HTTP server.
sbx create --name handbook-web shell
sbx exec handbook-web python3 --version
sbx ports handbook-web --publish 127.0.0.1:8088:8000
sbx ports handbook-web
sbx exec handbook-web python3 -m http.server 8000 --bind 0.0.0.0
The final command stays in the foreground. In a second host terminal, run curl --max-time 5 http://127.0.0.1:8088/ or open that URL in your host browser. Serve only the empty teaching workspace, not a directory containing secrets.
Stop the foreground server with Ctrl-C, then remove the mapping:
sbx ports handbook-web --unpublish 8088:8000
Inspect sbx ports handbook-web again. Port mapping changes on an existing sandbox belong to sbx ports; --publish on a reattach is ignored.
Expected observations
The host request reaches the guest’s HTTP server only while the process and mapping are active. The host port and guest port may differ. A bind conflict on 8088 means you should choose another unused host port, not stop an unrelated service.
Do not generalize a successful inbound request into permission for outbound traffic. For guest-to-host access, use the documented local-services workflow and a synthetic service; do not assume arbitrary host addresses are reachable.
Troubleshooting
Work from the inside outward: is the process running, on which address and port, is there a mapping, and is the host request using its actual host port? For outbound failures, inspect DNS and policy separately. ICMP is blocked; failed ping is not a useful proof that HTTPS is unavailable. UDP support is experimental and off by default, rather than categorically impossible.
Interview practice
Why can curl succeed inside the guest while the host browser fails?
The server may be reachable only on guest loopback, the mapping may be absent, or the host may use the wrong port. Describe the complete path instead of treating localhost as a universal address.
Does publishing a port grant outbound internet access?
No. Inbound forwarding and outbound policy solve different routing and authorization problems. Verify both independently.
Completion check
Draw both request directions, label each loopback address, and show the mapping removed after the exercise.
Sources and version notes
Checked 6 October 2026; current baseline: sbx v0.46.0. Architecture · Monitoring policies · Configure an upstream proxy
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.