aws / aws/aws-application-networking-k8s

Document how to block pod-to-pod direct communication except traffic to and from lattice fleet

Open
#87 1 comment 0 reactions 0 assignees View on GitHub
documentation needs investigation
Dominant language
Go
Stars
278
Forks
85
PR merge metrics
No merged PRs in 30d

Description

We need to add document on how to prevent following if customer desires to block them

"
I can bypass any Service level IAM auth policies within a cluster by calling the service "direct" using the kube dns host (app.namespace) rather than the app’s lattice host, as the request does not go via lattice so is not subject to its rules. Are there any thoughts here? As mentioned in the other queries it would be great if kube users just use kube dns styles hosts everywhere and the platform transparently routes them through lattice
"

Contributor guide

Open the contributing guide

Research direction

No documentation file or test is named in the issue. Start by locating the repository's documentation entry point and reviewing the Kubernetes pod-to-pod path and VPC Lattice fleet traffic described here. Done means the document explains how customers can block direct kube-DNS communication while permitting traffic to and from the Lattice fleet.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
documentation, networking, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.