Skip to content

Improve segmentation egress boundary gates#1693

Open
yZangEren wants to merge 1 commit into
UnitOneAI:mainfrom
yZangEren:improve/segmentation-egress-boundary-gates
Open

Improve segmentation egress boundary gates#1693
yZangEren wants to merge 1 commit into
UnitOneAI:mainfrom
yZangEren:improve/segmentation-egress-boundary-gates

Conversation

@yZangEren
Copy link
Copy Markdown

Closes #1685.

Scope

  • Adds v1.1.0 egress boundary guidance to skills/network/segmentation/SKILL.md.
  • Adds discovery patterns for NAT, egress, proxy, DNS, resolver, and service-mesh artifacts.
  • Adds a dedicated egress boundary and internet exit evidence step covering:
    • approved destination inventory;
    • enforcement point proof;
    • direct internet route and bypass review;
    • DNS path controls;
    • port-only outbound allowlist handling;
    • logging and exception lifecycle evidence.
  • Adds an Egress Boundary Matrix to the output template.
  • Updates findings classification and common pitfalls for unrestricted egress, proxy/DNS/service-mesh bypasses, broad NAT routes, and stale exceptions.

Validation

  • git diff --check
  • Markdown fence-balance check: 8 fences, balanced
  • ASCII check: 0 non-ASCII characters
  • Required marker checks for SEG-EGRESS-01, Egress Boundary Matrix, Direct Internet Route Review, and 1.1.0

Payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] segmentation: add egress boundary and internet exit evidence gates

1 participant