Skip to content

docs: 'no egress' → no tailnet egress; internet egress is open by default - #50

Merged
chaodu-agent merged 1 commit into
mainfrom
docs/egress-precision
Sep 30, 2026
Merged

chaodu-agent merged 1 commit into
mainfrom
docs/egress-precision

Conversation

@chaodu-agent

Copy link
Copy Markdown
Contributor

Correction from review. The pod has no tailnet egress (userspace sidecar, inbound-only), but internet egress is open by default: openab-pty's networkpolicy-no-tailnet-egress.yaml excludes only tailnet ranges and comments that DNS/image/internet keep working, and the ECS tasks use assignPublicIp: true. An injected agent therefore has a shell and outbound internet — it can exfiltrate whatever it reads.

Fixes:

  • ADR amendment + Decision: 'no egress' → 'no tailnet egress (internet open by default)'.
  • Requirement doc: same, plus the stale 'blocked by profile — sandbox omits exec' row (superseded by sandbox profile is not a boundary: GUI control is a shell #45) and the 'reaches other tailnet nodes: impossible' row (only if the node runs no tailscaled).
  • README reverse-attach intro.
  • Invariant wording: 'no host or cloud credential', not credential-free (the agent CLI's model login and e.g. git live in the container).
  • tool-profiles.md: classification covers local tools; upstream browser_* have their own allowlist and must be classified before a browser tier; the observe note now says the agent has outbound internet by default.

Docs only. Refs #45.

… default

Correction (thanks to review): the openab-pty pod has no *tailnet* egress
(userspace sidecar, inbound-only), but ordinary internet egress is open by
default — networkpolicy-no-tailnet-egress.yaml excludes only the tailnet
ranges, and the ECS tasks set assignPublicIp: true. So an injected agent has
a shell AND outbound internet: it can exfiltrate what it reads. Fixes the ADR
amendment, the requirement doc (incl. the stale 'blocked by profile' and the
tailscaled-on-node caveat), README, and the observe prompt-injection note.
Also: the invariant is 'no host credential', not credential-free (the agent's
model login and e.g. git live in the container); and classification covers
local tools — upstream browser_* have their own allowlist and must be
classified before a browser tier ships. No code change.
@chaodu-agent
chaodu-agent merged commit 3f65604 into main Sep 30, 2026
6 checks passed
@chaodu-agent
chaodu-agent deleted the docs/egress-precision branch September 30, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant