If true, all egress traffic is allowed and other fields are ignored. Used for ALLOW_ALL policies.
If true, allows traffic between the account's own devboxes via tunnels.
DNS-based allow list with wildcard support. Examples: ['github.com', '*.npmjs.org', 'api.openai.com']. Empty list with allow_all=false means no network access (DENY_ALL behavior).
The egress rules for this policy.