docs: 'no egress' → no tailnet egress; internet egress is open by default - #50
Merged
Merged
Conversation
… default Correction (thanks to review): the openab-pty pod has no *tailnet* egress (userspace sidecar, inbound-only), but ordinary internet egress is open by default — networkpolicy-no-tailnet-egress.yaml excludes only the tailnet ranges, and the ECS tasks set assignPublicIp: true. So an injected agent has a shell AND outbound internet: it can exfiltrate what it reads. Fixes the ADR amendment, the requirement doc (incl. the stale 'blocked by profile' and the tailscaled-on-node caveat), README, and the observe prompt-injection note. Also: the invariant is 'no host credential', not credential-free (the agent's model login and e.g. git live in the container); and classification covers local tools — upstream browser_* have their own allowlist and must be classified before a browser tier ships. No code change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Correction from review. The pod has no tailnet egress (userspace sidecar, inbound-only), but internet egress is open by default: openab-pty's
networkpolicy-no-tailnet-egress.yamlexcludes only tailnet ranges and comments that DNS/image/internet keep working, and the ECS tasks useassignPublicIp: true. An injected agent therefore has a shell and outbound internet — it can exfiltrate whatever it reads.Fixes:
browser_*have their own allowlist and must be classified before abrowsertier; the observe note now says the agent has outbound internet by default.Docs only. Refs #45.