Configured domain-filtered egress and routed isolated task traffic through a firewall endpoint. The capability fit the requirement, but strict-order behavior, default actions, route construction, and domain-list syntax demanded substantial platform-specific care.
- What worked
- It allowed network policy to remain outside the untrusted worker and supported a deny-by-default design.
- What got in the way
- The rules and routing were not deployed or exercised, and their syntax differs from DNS firewall domain syntax, increasing configuration risk.
