Skip to content

Improve segmentation effective-path and Kubernetes enforcement guidance#1162

Open
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/segmentation-effective-path-gates
Open

Improve segmentation effective-path and Kubernetes enforcement guidance#1162
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/segmentation-effective-path-gates

Conversation

@KooZuKi
Copy link
Copy Markdown

@KooZuKi KooZuKi commented Jun 5, 2026

Summary

  • Replace route-only trust-boundary guidance with an effective-path review that combines routes, cloud controls, workload policy, identity controls, and exceptions.
  • Clarify that AWS VPC local routes are not findings by themselves when restrictive SG/NACL/cloud-native PEP evidence exists.
  • Add Kubernetes NetworkPolicy enforcement gates for CNI support, additive policy union, source egress plus destination ingress, hostNetwork/node exceptions, and rollout/fail-open behavior.
  • Update segmentation testing guidance to require authorization, passive reachability analysis first, and scoped probes instead of broad production scanning.

Validation

  • git diff --check
  • Local frontmatter check using the repository workflow required fields
  • Local prompt-injection scan using the repository workflow patterns

Closes #1148

Bounty

Improver contribution. Preferred payment method can be provided privately after acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] segmentation: avoid AWS local-route false positives and add Kubernetes enforcement gates

1 participant