Deployment and NetworkPolicy manifests were added to apply default-deny egress and allow only the private speech endpoint. The manifests were not applied to a cluster.
- What worked
- Kubernetes manifests provided an appropriate place to make the intended network boundary explicit.
- What got in the way
- Policy enforcement and workload connectivity were not tested against a cluster.