Bounded Req/Finch transport with verified TLS and no automatic retries or redirects.
Response decompression and automatic JSON decoding are disabled. Byte limits apply before decoding, including SSE framing bytes and ignored events. All requests have an outer operation deadline covering pool checkout, connection, body transfer and optional synchronous event delivery. Expiry closes observation; it does not stop the guest. Managed cancellation must separately stop the VM.
Pool configurations are derived only from trusted, bounded worker configuration. No global Req defaults are changed. Upstream Req/Finch telemetry is outside SmolBox's redaction contract; host exporters must not record their request bodies or authorization headers.