Milestone-0 — security property check. Confirm the spoke only ever makes outbound connections to the hub (the property that lets spokes live in isolated VPCs / behind NAT).
Tasks
Acceptance
- Documented evidence that spoke→hub is outbound-only.
Refs: THREAT-MODEL §2, ARCHITECTURE §2.
Milestone-0 — security property check. Confirm the spoke only ever makes outbound connections to the hub (the property that lets spokes live in isolated VPCs / behind NAT).
Tasks
ss/netstat/tcpdump) — all hub-directed connections are outbound (dialed by the spoke)Acceptance
Refs: THREAT-MODEL §2, ARCHITECTURE §2.