03 ยท Close the bypass

Host containment for agent processes

Installs, verifies, and rolls back nftables-backed host containment.

Free agent-containment
Document source v3.5.0 release Manifest commit ca05ed06 Open manifest

Operator surface

Run the command

The release manifest records this command as the capability's operator entry point. Open the pinned source pointer to inspect the declaration and surrounding validation.

Command pipelock contain Read Cmd

Availability

Included tiers

Community Pro Enterprise
Deployment boundary

Kernel-enforced containment requires Linux, nftables, and the managed identities; other targets cannot provide this containment path.

Source records

Open the pinned source

The release manifest names these source pointers. The publication gate confirms their Go files and declarations exist at the same Pipelock commit as this page; the linked code provides the runtime context.

Read next

Guides and references