Skip to content

Support bidirectional host-loopback access #276

Description

Support network.ingress.hostLoopback: "allow" without requiring callers to supply a port-forwarding list.

Example Expected behaviour
Host-loopback access allowed The workload can reach services on host loopback, and the host can reach services listening inside the workload.
Host-loopback allowed, ingress.default: "deny" Host-loopback connections work, but other private-network inbound connections remain blocked.
Host-loopback access denied Block both directions between host loopback and the workload.
Host-loopback denied with a configured proxy Preserve only the existing outbound exception to the exact TCP proxy endpoint.

Do not expose workload listeners through the host's LAN/public interfaces. Keep loopback communication between processes inside the same sandbox separate from host-loopback access.

Verify both directions with real workloads. Existing explicit TCP/UDP forwards should continue to work.

MXC schema requirement: network.ingress.hostLoopback, with semantics defined in the networking contract.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions