aws / aws/aws-application-networking-k8s
Document how to block pod-to-pod direct communication except traffic to and from lattice fleet
- Dominant language
- Go
- Stars
- 278
- Forks
- 85
- PR merge metrics
- No merged PRs in 30d
Description
We need to add document on how to prevent following if customer desires to block them
"
I can bypass any Service level IAM auth policies within a cluster by calling the service "direct" using the kube dns host (app.namespace) rather than the app’s lattice host, as the request does not go via lattice so is not subject to its rules. Are there any thoughts here? As mentioned in the other queries it would be great if kube users just use kube dns styles hosts everywhere and the platform transparently routes them through lattice
"
Contributor guide
Research direction
No documentation file or test is named in the issue. Start by locating the repository's documentation entry point and reviewing the Kubernetes pod-to-pod path and VPC Lattice fleet traffic described here. Done means the document explains how customers can block direct kube-DNS communication while permitting traffic to and from the Lattice fleet.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- documentation, networking, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100