The business case · Egress control
Cilium network policy, by the risk it changes
Network policy for Kubernetes workloads. An egress rule puts the endpoint into default-deny for outbound traffic, and a DNS-name rule allows named destinations only. Written as an answer, the agent's workload reaches the destinations on the list and nothing else.
Open source: Apache-2.0 · CNCF · get involved
The deployment: The model's typical deployment, with the answers this project addresses stated as they are without it: can reach the general internet.
The model: the RiskGraph Explorer's 49 facts, 49 risks and 10 roles, copied into this site with its provenance; the register below is computed, not written. How.