Skip to content

Policy Management & Enforcement Support #369

Description

@abhisek

PMG grows two connected capabilities: (1) a generic policy evaluation engine (CEL over proto-defined contexts) enforced in the proxy lifecycle, and (2) proxy-enforced network control — the OS sandbox confines all outbound traffic to the PMG proxy (network_via_proxy_only), making the proxy the single enforcement point where per-host network policy finally becomes real (today, sandbox allow_outbound lists are documentation only: Seatbelt rejects non-localhost hosts, bubblewrap is binary).

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions