DevOps Professional · Module 5: Hybrid networks and hard integrations · Lab
Pick and Test Required Egress Flows Against a Fixture Allowlist
45 min hands-on · Core
A local lab namespace with an egress checkpoint and a fixture allowlist of three flows. No real third-party targets; unlisted destinations are lab-local sinks.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Record the default-open baseline as the fault
- Enforce the allowlist and quote allow/deny results
- Process one new flow request through owner and expiry
Step 1
Show the open field
Before enforcement, reach an unlisted lab-local sink from a test pod and quote the success as the baseline fault. Egress was never listed.
Step 2
Enforce and test
Apply the three-flow fixture allowlist with default deny. Quote each allowed flow succeeding and the unlisted sink dropping with the rule. Confirm DNS still serves the allowed flows.
Step 3
Request the fourth flow
File a new-flow request with reason and owner, approve or deny it with the reason recorded, and set or refuse expiry accordingly. The decision enters the record either way.
How to confirm it worked
- Open baseline quoted as the fault
- Allowed flows quoted succeeding, unlisted quoted denied
- New-flow request processed with owner, reason and expiry