Skip to main content
Version: Next

Isolate workloads

Different controls apply to gateway destinations, hosted workloads, and tunnel machines.

ControlScope
Gateway localhost/private/link-local restrictionsDirect MCP destination validation by Obot
Kubernetes MCP NetworkPolicySelected MCP pods in the MCP namespace; does not restrict the Obot server itself
Pod Security Admission and RuntimeClassPod admission and execution isolation on configured Kubernetes nodes
Domain egress providerPer-server hosted MCP domain allowlists; currently Aviatrix, with HTTPS/443 restrictions
Tunnel allowed URLsDestinations reached by the tunnel machine; ordinary direct-gateway destination restrictions do not apply there

Keep MCP NetworkPolicy and pod-security settings enabled unless a reviewed workload requires an exception. RuntimeClass requires the corresponding runtime to be installed on eligible nodes.

Domain-based egress is separate from the built-in IP-based policy. Its remote endpoints are not hosted workloads and are not covered by this feature.

Obot itself needs connectivity to its database, identity provider, upstream services, storage, and possibly cloud credential metadata. Scope any operator-managed server-egress policy to those dependencies; do not assume a blanket private-IP block is compatible with your topology.

Docker's mounted socket provides host-level container management. Use it for trusted evaluation. For private remote services, review tunnel security.