Etai Lev Ran
Etai Lev Ran
Currently using a mix of generic and per target rules - Extract common patterns (e.g., .dockerfile or /Dockerfile) with generic rules - Simplify Dockerfiles based on distrolless/alpine with multiple stages...
See #61 for details
Current policy denies are closed normally and may result in weird client behavior (e.g., failed TLS). It may be better to cause reset to connection (which could end up as...
Based on Go language style recommendations: - Error messages included in `error` return values (which can be passed up the stack and concatenated with other errors) should start with a...
Based on discussions, seems that we can't currently support a (useful?) construct that allows only specific to/from (e.g., "allow ssh only to workload X"). As it could be thought of...