Dome Systems

Cloudflare container MCP server and Dome

Let agents run code. Decide which ones, and for how long.

Cloudflare hosts an MCP server that gives an agent its own container to run commands and edit files in. Connect it to Dome once, and rules decide which agents may execute and how long a command may run. Every command lands in one audit trail.

EngineersAgentsDomeCloudflare containersCallersEngineersAgentsdata-analystAgentstest-runnerAgentsreport-writerGatewayscompute-gatewaycontainer_execCommandsContainer filesRead and writeModel poolAny providerRulesGuardsAuditsaudit-trail
data-analyst→cloudflare-containers/container_file_write· as m.okaforAllowed

How Dome helps

Dome provides a governed gateway for Cloudflare Containers

Execution decided per agent

Rules name the agents that may run commands in a container. Give the rest file reads, or nothing.

A ceiling on every command

Rules read the timeout on each container_exec call. A command with no timeout, or one over a minute, is refused.

Each command on the record

Audit records every command, file write and refusal under the agent that made it. One trail covers code, tools and models.

Get started

Cloudflare containers behind the Gateway in three steps

Add the hosted server, sign in and sync its tools, and apply the rules. Dome registers its own OAuth client with Cloudflare.

  1. 01

    Add the container MCP server

    Credentials are per user, through Cloudflare OAuth. Each container belongs to the account that signed in.

    $ dome tools add --name cloudflare-containers \
    --url https://containers.mcp.cloudflare.com/mcp \
    --auth-method oauth --credential-type per-user \
    --oauth-authorize-url https://containers.mcp.cloudflare.com/oauth/authorize \
    --oauth-token-url https://containers.mcp.cloudflare.com/token \
    --oauth-registration-url https://containers.mcp.cloudflare.com/register \
    --gateway compute-gateway
  2. 02

    Sync the catalog

    Sync spends your own Cloudflare credential, so sign in first. Until then it fails and agents get “tool not available in this gateway”.

    $ dome tools catalog sync cloudflare-containers
  3. 03

    Apply the rules

    Scope them to one agent while you try them. Simulate before you deploy.

    $ dome rules apply cloudflare-exec.cedar \
    --agent data-analyst --name cloudflare-exec

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Cloudflare Containers itself, see Cloudflare's documentation.

Rules

Run commands, one minute at a time

The permit opens five container tools to the agent. The first forbid refuses every other tool, file deletes included, and the second refuses any command without a timeout of 60 seconds or less.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "cloudflare-containers" &&
["container_initialize", "container_exec", "container_file_write",
"container_file_read", "container_files_list"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "cloudflare-containers" &&
!["container_initialize", "container_exec", "container_file_write",
"container_file_read", "container_files_list"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "cloudflare-containers" &&
resource.tool_name == "container_exec" &&
!(resource has arguments &&
resource.arguments has timeout &&
resource.arguments.timeout <= 60000)
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Timeout

agent data-analyst · acting as m.okafor
cloudflare-containers/container_exec(args: "python3 churn.py", timeout: 30000)
  1. Agentdata-analyst is registered and active
  2. Toolcontainer_exec is open to data-analyst
  3. RuleTimeout is 60 seconds or less
DecisionAllowed

Example agents

Three agents on Cloudflare containers

Each one gets the container tools its job needs. Only two may run commands.

data-analyst

Analyze exports

Writes a CSV export into its container, runs a Python script over it and reads back the result. Each command stops within a minute.

  • cloudflare-containers/container_file_write
  • cloudflare-containers/container_exec
  • cloudflare-containers/container_file_read

test-runner

Run a test suite

Starts a fresh container, writes the files under test and runs the suite. Results go back to the engineer who asked.

  • cloudflare-containers/container_initialize
  • cloudflare-containers/container_file_write
  • cloudflare-containers/container_exec

report-writer

Read results

Lists and reads the files other runs left behind and drafts a summary. It never executes a command.

  • cloudflare-containers/container_files_list
  • cloudflare-containers/container_file_read

Agent workflow

Bringing it together

Connecting Cloudflare Containers to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

Agent service

Cloudflare Containers

This page

MCP server

GitHub

See how

FAQ

Common questions

Does Cloudflare have an MCP server for sandboxed code execution?

Yes. Cloudflare hosts a container server at containers.mcp.cloudflare.com/mcp, and Dome adds it by URL with Cloudflare OAuth.

Can I limit how long an agent's command runs?

Yes. Rules read the timeout argument on container_exec, so a command over the ceiling, or with none set, is refused.

Can a rule turn off internet access in the container?

No. The server's tools take no network or template argument, so rules decide on the agent, the tool and the timeout.

Can an agent read container files without running code?

Yes. Allow container_files_list and container_file_read and leave container_exec out.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.