Deny by default
Agent workloads have no direct route to the internet or to your network.
WhereConsole
Introduced Jun 3, 2026
agent workload
✓ llm proxy model calls
✓ egress gateway the rest
✗ direct internet — no route exists
How it works
No third path.
Outbound traffic goes through the LLM proxy for model calls and the egress gateway for everything else. A destination with no rule has no route.
Certificates, not tokens.
Workloads authenticate to the gateways with an x509 certificate the platform mints per workload — not a credential a model could read.
Compromise stays contained.
A prompt-injected agent still cannot reach beyond its own allow list.
See it on your own cluster.
Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.