How it works
QEMU usesslirp by default on macOS and Linux. Slirp is a user-mode network built into QEMU, so it needs no administrator privileges or host network device.
Firecracker and explicit QEMU qemu_network="tap" use a TAP device on Linux. A TAP device is a virtual network interface connecting one sandbox to the host. The sandbox receives a private IP address and uses network address translation (NAT) to reach the internet through the host.
On the Linux TAP path, each sandbox receives:
- Guest IP: an address in the
172.16.0.2–172.16.0.255range - Gateway:
172.16.0.1(the host side of the TAP device) - Netmask:
255.255.255.0(/24)
Sandbox isolation
Sandboxes are isolated from each other by default. On Linux TAP, Celesto adds a firewall rule that drops traffic between sandbox interfaces:- Access the internet via NAT
- Be reached from the host via port forwarding
- Not communicate directly with other sandboxes
Use Network controls to turn outbound access off or allow specific destinations. QEMU off mode works with the default network on macOS and Linux; restricted IPv4 destinations require explicit TAP networking on Linux.
TAP devices
A TAP device is a virtual network interface that connects a sandbox to the host networking stack. Celesto creates one TAP device per sandbox and removes it when the sandbox is deleted. The lifecycle of a TAP device:- Create — Celesto runs
ip tuntap addto create a virtual interface - Configure — assigns the host-side IP and brings the link up
- Route — adds a host route so packets reach the sandbox
- Cleanup — deletes the TAP device when the sandbox stops
Linux TAP NAT and firewall rules
For Firecracker and QEMU TAP, Celesto uses nftables to manage NAT and firewall rules. It creates two tables:ip smolvm_nat— handles NAT (masquerade for outbound traffic, DNAT for port forwarding)inet smolvm_filter— handles forwarding rules and sandbox isolation
- Enables IP forwarding on the host (
net.ipv4.ip_forward=1) - Adds a masquerade rule so outbound traffic appears to come from the host
- Adds a forwarding rule to allow traffic from the sandbox’s TAP device to the internet
- Adds an isolation rule to block sandbox-to-sandbox traffic
Port forwarding
Celesto supports two types of port forwarding to reach services running inside a sandbox.SSH port forwarding
When a sandbox uses SSH, Celesto makes its SSH port reachable from the host. QEMUslirp uses QEMU’s built-in host forwarding. Linux TAP uses a localhost nftables rule.
You can connect manually with the assigned host port:
vsock command connection through vm.run().
Application port forwarding
To access a web server, database, or other service running inside a sandbox, useexpose_local():
slirp uses QEMU’s built-in forwarding. Linux TAP uses a localhost nftables rule. Both keep the service private to your machine.
The following diagram shows the Linux TAP path:
Applications should listen on 0.0.0.0 inside the sandbox. For an application that listens only on guest 127.0.0.1, pass guest_loopback=True; this uses an SSH tunnel.
See the port forwarding guide for more examples including automatic port allocation, multiple forwards, and troubleshooting.
Linux TAP prerequisites
Firecracker and QEMU TAP need the following tools on Linux:ip(from iproute2) — manages TAP devices and routesnft(from nftables) — manages NAT and firewall rulessudoaccess for networking commands
celesto setup command installs these automatically. You can verify your setup with:
Troubleshooting
Sandbox has no internet access
Sandbox has no internet access
Check that IP forwarding is enabled and NAT rules are in place:
'ip' or 'nft' command not found
'ip' or 'nft' command not found
Install the missing package:
Permission denied on TAP creation
Permission denied on TAP creation
Run the Celesto system setup to configure sudo permissions:
Port forwarding not working
Port forwarding not working
Check that Also verify that the service inside the sandbox is binding to
route_localnet is enabled for the TAP device and forwarding rules exist:0.0.0.0, not 127.0.0.1.TAP device persists after sandbox deletion
TAP device persists after sandbox deletion
If cleanup failed, remove the device manually:
Next steps
- Review the security model
- Choose your backend (Firecracker vs. QEMU)
- Read the architecture overview
