Skip to main content
Prepare files in one operation, save the resulting image, then verify those files in a new operation with networking disabled. This recipe uses Python to call the REST API, where networking.enabled controls the guest network interface. The setting defaults to true and must be chosen for each operation.

Prerequisites

Complete Set up access. Export NEBIUS_API_KEY, NEBIUS_PROJECT_ID, and an immutable IMAGE_UUID containing /bin/sh and the cat, mkdir, test, and printf commands. In a new local directory, create a Python project:
The client keeps the API credential locally. It is not passed to guest code.

Follow the workflow

  1. Prepare /fixture/expected.txt with networking enabled and disposable=False.
  2. Keep the returned image UUID. It supplies the prepared files to the next operation.
  3. Run verification from that image with networking=False and disposable=True.
The verification checks the file contents and confirms that /sys/class/net contains no interface other than loopback. It does not depend on reaching an external host. Saving the preparation image carries the files into the second operation; it does not carry the earlier network setting.

Run the complete example

Save the program as verify_no_network.py and run uv run python verify_no_network.py. Start with main(): it describes the two operations. The run_operation() helper submits each request once, prints its ID, and polls with a 90-second deadline. Each guest command has a 30-second execution limit. Expected output includes two operation IDs, the saved checkpoint UUID, and:
The preparation checkpoint remains subject to image retention. The verification returns no saved image because it is disposable. To adapt the recipe, replace PREPARE_INPUTS and VERIFY_OFFLINE while keeping the saved-image check and the network setting on the verification operation. If a request fails or polling reaches its deadline, inspect the printed operation ID before resubmitting. Polling failure does not cancel accepted work. If submission fails before an ID is returned, resolve that uncertain outcome before repeating the POST. The remote execution limit still bounds an accepted workload. A failed verification may indicate a missing or incorrect fixture, or an unexpected guest interface. Keep the operation and image IDs with the redacted process result when investigating. Disabling networking applies to the whole operation, including its subprocesses. Use it when verification can run entirely offline. See Configure networking and secrets and the spawn API reference.