Review compensating control: tailscale-network-isolation
Verified: tailscale serve status shows only svc:k8s, ACLs restrict tag:flyio-target to port 443 with admin/operator ownership only, indri has no flyio-target tag. All 10 muted findings remain valid. Noted gap: no automated alerting on new flyio-target devices. Tracked in Todoist as MC4 (Manual Compliance Control Check CronJob). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
18fe172a54
commit
59f3422d3e
1 changed files with 1 additions and 1 deletions
|
|
@ -31,7 +31,7 @@ controls:
|
|||
identity with ACL enforcement. Profiling endpoints, debug ports,
|
||||
and control-plane APIs are unreachable from the public internet.
|
||||
created: 2026-03-30
|
||||
last-reviewed: 2026-03-30
|
||||
last-reviewed: 2026-04-06
|
||||
notes: >-
|
||||
Verify with 'tailscale serve status --json' on indri and review
|
||||
Tailscale ACLs in pulumi/tailscale/. Only tag:flyio-target services
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue