Skip to content

FR: optional documented egress allowlist (model API, git, registries) #47

Description

@chaodu-agent

The pod has no tailnet egress (userspace sidecar, inbound-only — #37), but ordinary internet egress is open by default: deploy/k8s/networkpolicy-no-tailnet-egress.yaml excludes only the tailnet ranges (its comment notes DNS/image/internet keep working), and deploy/ecs/{service,pty-kiro,kiro-with-pty}.yaml set assignPublicIp: true.

Open internet egress is the right default — the agent CLI needs its model API, git remotes and package registries. But a compromised or prompt-injected shell then has both code execution and unrestricted outbound, so it can exfiltrate anything it reads. Deployments handling sensitive work should be able to opt into an allowlist.

Ask: a documented, opt-in egress allowlist limiting the pod to model-API hosts, git remotes and package registries.

  • k8s: NetworkPolicy is L3/L4 only (IP/port), so a hostname allowlist needs a CNI that supports DNS/FQDN egress rules (Cilium toFQDNs, Calico DNS policy) or an egress proxy the pod is pointed at. Ship an example manifest + the list of default-needed hosts (the model API for the configured agent, common git hosts, npm/PyPI/crates/apt).
  • ECS: a restrictive security group won't do hostnames either; document the proxy pattern (egress via a filtering proxy, or PrivateLink/NAT with an allowlist) and the env to point the agent at it.
  • Pair it with networkpolicy-no-tailnet-egress.yaml so a homelab node running tailscaled closes both the tailnet path and unlisted internet egress.

Context: instance-mcp #45 (profiles are not a boundary; observe protects the computer, not the agent) and its docs/tool-profiles.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions