← Back to context

Comment by githubnuoo

6 hours ago

how does it do it?

proxy in the middle (but cert pinning problems)

or DNS filtering? (but agent could have "memorized" stable IP)

Cert pinning: not a problem. we don't decrypt traffic, we just pass it through. The only exception is hosts you give a credential to, since we have to insert the key.

Memorized IP: doesn't work, the vm can only connect to an IP if it came from a DNS lookup of an allowed name. Any other IP is blocked.

A bit of "shared responsibility" philosophy kicking through but I try to have good defaults