edu
edu copied to clipboard
Egress filtering for terminal environment
Is your feature request related to a problem? Please describe. The terminal environment doesn't have any real restrictions on egressing traffic.
Describe the solution you'd like An HTTP/HTTPS proxy, accessed via environment variables for pods that point to a sidecar pod-based service in the same namespace.
Describe alternatives you've considered A standalone gateway VM with firewall rules.
Additional context This suggestion came out of a discussion about the terminal environment and a quick, try to break it session, with @jedsalazar earlier in the week. This proxy configuration will be a quick and important improvement to the overall security of the environment.