Volter World

Route Python and native clients through a World

A Node preload does not intercept Python, curl, Go or a native binary. Those clients must honor the World's proxy and session CA, or a vendor-supported endpoint override. Being launched in a World does not by itself prove every network call was routed.

A Python request to the real vendor hostname

Use Node 22.6 or newer, npm and Python 3 in an empty directory. The example first creates a customer using the real Node SDK, then reads it from Python through the scoped HTTPS proxy.

package.json
{
  "name": "acme-web",
  "private": true,
  "type": "module",
  "dependencies": {
    "stripe": "17.7.0"
  },
  "devDependencies": {
    "@volter/world": "3.0.63",
    "@volter/twin-stripe": "3.0.1"
  }
}
.env.example
STRIPE_SECRET_KEY=
check.mjs
import assert from 'node:assert/strict';
import Stripe from 'stripe';
const stripe = new Stripe(process.env.STRIPE_SECRET_KEY, { maxNetworkRetries: 0 });
const made = await stripe.customers.create({ email: 'ada@example.com', name: 'Ada' });
assert.equal((await stripe.customers.retrieve(made.id)).email, 'ada@example.com');
assert.equal(made.created, Date.parse('2026-01-15T12:00:00Z') / 1000);
console.log('create, read and frozen timestamp passed');
read-customer.py
import json, os, ssl, urllib.request
proxy = os.environ.get('HTTPS_PROXY') or os.environ.get('https_proxy')
ca = os.environ.get('CURL_CA_BUNDLE') or os.environ.get('SSL_CERT_FILE')
if not proxy or not ca: raise RuntimeError('Expected the World proxy and its session CA')
client = urllib.request.build_opener(urllib.request.ProxyHandler({'https': proxy}), urllib.request.HTTPSHandler(context=ssl.create_default_context(cafile=ca)))
request = urllib.request.Request('https://api.stripe.com/v1/customers', headers={'Authorization': 'Bearer ' + os.environ['STRIPE_SECRET_KEY']})
with client.open(request) as response: customers = json.load(response)
assert any(c.get('email') == 'ada@example.com' for c in customers['data'])
print('Python real-hostname request read the seeded customer')
npm install
npx volter world init --name native-client --twins stripe
npx volter world up
npx volter world clock set 2026-01-15T12:00:00Z
npx volter world run -- node check.mjs
npx volter world run -- python3 read-customer.py
Python real-hostname request read the seeded customer

The Python code explicitly uses the inherited proxy and its CA. It calls api.stripe.com, keeps TLS verification enabled, and receives the same stored customer. It uses only Python's standard library. Do not print the proxy environment, bearer keys or CA custody into a bug report.

npx volter world log
npx volter world down

Other clients

Client behaviorConfigureVerify
Honors HTTPS_PROXY and a CA pathRun through the World; select that client's supported trust variable or explicit CA optionA vendor request and expected state/log result
Has its own SDK/CLI endpoint overrideUse the override declared by the twin, such as AWS_ENDPOINT_URLThe selected endpoint, SDK result and log
Ignores proxy variablesSet its documented proxy/CA options, or a supported explicit endpointDo not infer routing from the parent shell
Uses raw sockets, native DNS or an unsupported transportUse the appropriate enforced Machine/executor boundary when isolation is requiredActual boundary evidence; cooperative sandbox alone is insufficient

npx volter world shell opens a subshell with World routing. eval "$(npx volter world activate)" activates a compatible shell; deactivate restores it. Prefer world run for bounded scripts so the caller's shell is not left activated. Closing a shell does not tear down the World.

A CA trusted through environment variables is scoped to cooperating clients, not installed into the system trust store. Never turn off TLS verification to get a request through. Sandbox mode refuses untwinned destinations in cooperating clients, but cannot constrain a binary that ignores its mediation. See transport coverage, CLI for remote commands, and recovery for diagnostic commands.

View Markdown source

On this page