# Images, secrets and egress

Canonical: https://savrn.com/cloud/docs/sandboxes-images-secrets-egress

SAVRN Cloud · Coming soon. Public documentation and a browser simulation are available; connected services are not yet available.

A successful task output cannot prove that its runtime respected a security boundary. This SAVRN Cloud guide explains how image identity, narrowly scoped credentials and permitted outbound destinations fit into the evidence required for connected sandbox execution.

**SAVRN Cloud · Coming soon · Public preview · Browser-local simulation · No live compute or payments**

## Review the local configuration

Open [Sandboxes](https://savrn.com/cloud/console/#/sandboxes) and inspect the resource fields and sample task behavior. The demonstration can show a selected image or runtime description without downloading or executing it. Likewise, a network or secret setting represents intended configuration, not enforced isolation.

Use invented placeholder values when discussing credentials. Never enter a production key to test the interface. The [Keys](https://savrn.com/cloud/console/#/keys) screen issues only local simulated values; those values do not grant access to a provider.

## Describe a bounded task

A useful task has one approved runtime, a known input set, a limited output location and a short lifetime. It should need only the minimum tools and outbound destinations required for its purpose. A literature-scoring fixture, for example, can operate on synthetic local text without internet access.

Record the desired boundary before reviewing the result. A successful task output cannot establish whether the boundary held.

## Before connected services launch

Pin images by verified digest and review their origin. Inject short-lived, job-scoped secrets without exposing them to unrelated tenants or logs. Deny access to management networks and host files; allow outbound traffic deliberately. Test restrictions from inside the real execution environment. Define dependency acquisition, registry access, image updates and revocation. Any change to the runtime or network policy may require renewed qualification. Retain redacted evidence of enforcement, expiry and cleanup.
