Skip to content

Improve segmentation service mesh bypass gates#1936

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/segmentation-mesh-bypass-hostnetwork-1916
Open

Improve segmentation service mesh bypass gates#1936
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/segmentation-mesh-bypass-hostnetwork-1916

Conversation

@DENGXUELIN
Copy link
Copy Markdown

Summary

  • add a service mesh bypass evidence gate for hostNetwork, hostPort, sidecar injection, strict mTLS, CNI enforcement, node-local paths, and exception expiry
  • extend the micro-segmentation readiness and report output fields for mesh bypass and default-deny evidence
  • add vulnerable and benign segmentation fixtures covering host-network mesh bypass and strict default-deny controls

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence balance check
  • Added-line ASCII check
  • Content marker check for service mesh bypass, hostNetwork, hostPort, default-deny, CNI enforcement, sidecar injection, mTLS, exception owner, and expiry
  • git merge-tree --write-tree origin/main HEAD

Closes #1916

Bounty request: Improver Moderate / USD 100 if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] segmentation: add service-mesh bypass and host-network gates

1 participant