How ready are your agents for a bad day? Get your score

Port exposure

Publish a service running inside a workload to your platform's private network.

WhereSandboxesCLI

Introduced Apr 11, 2026 · updated Aug 10, 2026

Ports:3000
calm-tiger-533306e4.acme.agyn
:3000http://…acme.agyn:3000
Expose a port
Open from a device enrolled on the platform network. Anyone else on it can reach these too.

How it works

A URL, not a tunnel.

Expose a port and the service gets an address on your platform network — open it in a browser tab. No SSH forwarding, no third-party tunnels.

Enrolled devices only.

Any device enrolled on the network can open it — handy for showing a teammate — while the public internet cannot reach it at all.

Revoke one machine, keep the rest.

Devices enroll per machine, so pulling one laptop's access doesn't disturb anyone else's.

See it on your own cluster.

Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.