Post #3259705
2026-06-06 16:03 UTC
Previously, I used Cilium's Hubble feature to do this in the kubernetes cluster.
That project took a very similar approach, but actually was able to go into more detail, because it was trivial to do domain matching on egress policies.
It was followed by a aggressive lockdown of kubernetes containers to minimize every container to the absolute privilege/capabilities needed to function, which required some new tooling and quite a bit leaned, along with some open PRs and honestly simple MRs that I should get off my ass and submit
Replies (0)
No replies.