The pod has no tailnet egress (userspace sidecar, inbound-only — #37), but ordinary internet egress is open by default: deploy/k8s/networkpolicy-no-tailnet-egress.yaml excludes only the tailnet ranges (its comment notes DNS/image/internet keep working), and deploy/ecs/{service,pty-kiro,kiro-with-pty}.yaml set assignPublicIp: true.
Open internet egress is the right default — the agent CLI needs its model API, git remotes and package registries. But a compromised or prompt-injected shell then has both code execution and unrestricted outbound, so it can exfiltrate anything it reads. Deployments handling sensitive work should be able to opt into an allowlist.
Ask: a documented, opt-in egress allowlist limiting the pod to model-API hosts, git remotes and package registries.
- k8s: NetworkPolicy is L3/L4 only (IP/port), so a hostname allowlist needs a CNI that supports DNS/FQDN egress rules (Cilium
toFQDNs, Calico DNS policy) or an egress proxy the pod is pointed at. Ship an example manifest + the list of default-needed hosts (the model API for the configured agent, common git hosts, npm/PyPI/crates/apt).
- ECS: a restrictive security group won't do hostnames either; document the proxy pattern (egress via a filtering proxy, or PrivateLink/NAT with an allowlist) and the env to point the agent at it.
- Pair it with
networkpolicy-no-tailnet-egress.yaml so a homelab node running tailscaled closes both the tailnet path and unlisted internet egress.
Context: instance-mcp #45 (profiles are not a boundary; observe protects the computer, not the agent) and its docs/tool-profiles.md.
The pod has no tailnet egress (userspace sidecar, inbound-only — #37), but ordinary internet egress is open by default:
deploy/k8s/networkpolicy-no-tailnet-egress.yamlexcludes only the tailnet ranges (its comment notes DNS/image/internet keep working), anddeploy/ecs/{service,pty-kiro,kiro-with-pty}.yamlsetassignPublicIp: true.Open internet egress is the right default — the agent CLI needs its model API, git remotes and package registries. But a compromised or prompt-injected shell then has both code execution and unrestricted outbound, so it can exfiltrate anything it reads. Deployments handling sensitive work should be able to opt into an allowlist.
Ask: a documented, opt-in egress allowlist limiting the pod to model-API hosts, git remotes and package registries.
toFQDNs, Calico DNS policy) or an egress proxy the pod is pointed at. Ship an example manifest + the list of default-needed hosts (the model API for the configured agent, common git hosts, npm/PyPI/crates/apt).networkpolicy-no-tailnet-egress.yamlso a homelab node runningtailscaledcloses both the tailnet path and unlisted internet egress.Context: instance-mcp #45 (profiles are not a boundary;
observeprotects the computer, not the agent) and itsdocs/tool-profiles.md.