SNAS: A Multi-Layer Defense-in-Depth Architecture for Secure Egress in Sandboxed Workloads

📅 2026-06-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work proposes a secure and transparent egress solution for sandboxed workloads to ensure multi-tenant isolation and fair resource allocation. By constructing a defense-in-depth architecture that integrates eBPF-based packet filtering, GENEVE overlay networking, and distributed egress proxies, the system enables policy-driven network access control with low overhead. A novel two-tier policy enforcement mechanism is introduced: at the lower layer, eBPF enforces precise bandwidth rate-limiting using the Earliest Departure Time (EDT) algorithm, while the upper layer provides protections against connection exhaustion and port depletion. Deployed across all Snowflake regions, the system supports petabyte-scale data transfers and low-latency external integrations, meeting the stringent security and performance requirements of large-scale production environments.
📝 Abstract
Snowpark enables data engineering and AI/ML workloads in Snowflake by executing user-defined functions in secure sandboxes. Many of these workloads require external connectivity to access cloud APIs, external databases, or feature stores, creating a dependability challenge: how to provide transparent network access while preserving strict multi-tenant isolation and resource fairness. This paper presents Secure Network Access in Snowpark (SNAS), a production architecture for secure external communication from sandboxed workloads. SNAS combines Extended Berkeley Packet Filter (eBPF) packet filtering, Generic Network Virtualization Encapsulation (GENEVE) overlay networks, and distributed egress proxies for policy-driven egress control with low overhead. We describe the design, deployment, and measured production behavior of SNAS, including an eBPF-based bandwidth limiter using the Earliest Departure Time (EDT) algorithm, dual-tier policy enforcement, and safeguards for connection limiting and port exhaustion. SNAS is deployed across all Snowflake regions and supports large-scale production workloads including petabyte-scale data transfer and latency-sensitive external integrations.
Problem

Research questions and friction points this paper is trying to address.

secure egress
sandboxed workloads
multi-tenant isolation
external connectivity
resource fairness
Innovation

Methods, ideas, or system contributions that make the work stand out.

eBPF
GENEVE
egress control
defense-in-depth
bandwidth limiting
🔎 Similar Papers
No similar papers found.
N
Niranjan Kumar Sharma
Snowflake Inc.
S
S Muralidhar
Snowflake Inc.
S
Samy Boshra-Riad
Snowflake Inc.
M
Mike Halcrow
Snowflake Inc.
Y
Yuxiong He
Snowflake Inc.
N
Nitya Kumar Sharma
Snowflake Inc.
S
Shawn Xia
Snowflake Inc.
H
Haowei Yu
Snowflake Inc.
E
Elliott Brossard
Snowflake Inc.
D
Derek Denny-Brown
Snowflake Inc.
C
Choden Konigsmark
Snowflake Inc.
B
Bhanu Prakash
Snowflake Inc.
B
Brandon Baker
Snowflake Inc.
A
Andong Zhan
Snowflake Inc.