egress_guard

Outbound network control by domain/IP policy.


What it mitigates


Profilestrategy
localstrict allowlist
standardallowlist for critical paths, blocklist for known bad
unboundedmonitor and log aggressively

Minimal config

moduleConfig:
  egress_guard:
    # Choose one mode for predictability:
    # allowedDomains:
    #   - "api.openai.com"
    #   - "example.org"
    # blockedDomains:
    #   - "*.pastebin.com"

Design guidance