UNCLASSIFIED - NO CUI

Skip to content

bb-common should use the k8s endpointslice to determine ports for the kubeAPI definition

Motivation

bb-common's default kubeAPI definition is lax and allows all outbound traffic to traditional private ipv4 space. In order to lock this down a little tighter, the default definition should also specify ports determined by performing a helm lookup on the kubernetes service's EndpointSlice.

Acceptance Criteria

  • The default kubeAPI definition must specify ports determined by performing a lookup on the kubernetes service's EndpointSlice.
Edited by Zach Callahan