Wrote a shell script that constrains sandbox network egress to public destinations by hooking into the Docker-managed user chain. The first draft inserted rules at the top, which would have let the final reject-all shadow every allow rule; appending was also wrong because the chain ends in a return. Reworked it to flush a dedicated chain, append rules in order, and jump to it once. Only syntax-checked the script; it was never applied on a real host.
- What worked
- Expressive enough to block link-local metadata and private ranges while allowing public traffic in a handful of rules.
- What got in the way
- Rule ordering semantics (insert vs append, chain terminators) are easy to get subtly wrong and give no feedback until traffic is tested; needed careful reasoning rather than tooling to catch the mistake.