Cloudflare container MCP server and Dome
Let agents run code. Decide which ones, and for how long.
Cloudflare hosts an MCP server that gives an agent its own container to run commands and edit files in. Connect it to Dome once, and rules decide which agents may execute and how long a command may run. Every command lands in one audit trail.
How Dome helps
Dome provides a governed gateway for Cloudflare Containers
Execution decided per agent
Rules name the agents that may run commands in a container. Give the rest file reads, or nothing.
A ceiling on every command
Rules read the timeout on each container_exec call. A command with no timeout, or one over a minute, is refused.
Each command on the record
Audit records every command, file write and refusal under the agent that made it. One trail covers code, tools and models.
Get started
Cloudflare containers behind the Gateway in three steps
Add the hosted server, sign in and sync its tools, and apply the rules. Dome registers its own OAuth client with Cloudflare.
01
Add the container MCP server
Credentials are per user, through Cloudflare OAuth. Each container belongs to the account that signed in.
$ dome tools add --name cloudflare-containers \--url https://containers.mcp.cloudflare.com/mcp \--auth-method oauth --credential-type per-user \--oauth-authorize-url https://containers.mcp.cloudflare.com/oauth/authorize \--oauth-token-url https://containers.mcp.cloudflare.com/token \--oauth-registration-url https://containers.mcp.cloudflare.com/register \--gateway compute-gateway02
Sync the catalog
Sync spends your own Cloudflare credential, so sign in first. Until then it fails and agents get “tool not available in this gateway”.
$ dome tools catalog sync cloudflare-containers03
Apply the rules
Scope them to one agent while you try them. Simulate before you deploy.
$ dome rules apply cloudflare-exec.cedar \--agent data-analyst --name cloudflare-exec
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Cloudflare Containers itself, see Cloudflare's documentation.
Rules
Run commands, one minute at a time
The permit opens five container tools to the agent. The first forbid refuses every other tool, file deletes included, and the second refuses any command without a timeout of 60 seconds or less.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "cloudflare-containers" && ["container_initialize", "container_exec", "container_file_write", "container_file_read", "container_files_list"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "cloudflare-containers" && !["container_initialize", "container_exec", "container_file_write", "container_file_read", "container_files_list"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "cloudflare-containers" && resource.tool_name == "container_exec" && !(resource has arguments && resource.arguments has timeout && resource.arguments.timeout <= 60000)};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Timeout
- Agentdata-analyst is registered and active
- Toolcontainer_exec is open to data-analyst
- RuleTimeout is 60 seconds or less
Example agents
Three agents on Cloudflare containers
Each one gets the container tools its job needs. Only two may run commands.
data-analyst
Analyze exports
Writes a CSV export into its container, runs a Python script over it and reads back the result. Each command stops within a minute.
- cloudflare-containers/container_file_write
- cloudflare-containers/container_exec
- cloudflare-containers/container_file_read
test-runner
Run a test suite
Starts a fresh container, writes the files under test and runs the suite. Results go back to the engineer who asked.
- cloudflare-containers/container_initialize
- cloudflare-containers/container_file_write
- cloudflare-containers/container_exec
report-writer
Read results
Lists and reads the files other runs left behind and drafts a summary. It never executes a command.
- cloudflare-containers/container_files_list
- cloudflare-containers/container_file_read
Agent workflow
Bringing it together
Connecting Cloudflare Containers to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Cloudflare Containers
This page
MCP server
GitHub
See how
Models
FAQ
Common questions
Does Cloudflare have an MCP server for sandboxed code execution?
Yes. Cloudflare hosts a container server at containers.mcp.cloudflare.com/mcp, and Dome adds it by URL with Cloudflare OAuth.
Can I limit how long an agent's command runs?
Yes. Rules read the timeout argument on container_exec, so a command over the ceiling, or with none set, is refused.
Can a rule turn off internet access in the container?
No. The server's tools take no network or template argument, so rules decide on the agent, the tool and the timeout.
Can an agent read container files without running code?
Yes. Allow container_files_list and container_file_read and leave container_exec out.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all