Allow SecurityService egress to the dev machine agent, and apply policies from CI

FixKlusterServices
Shipped
August 15, 2026 at 9:45 PM UTC
Author
Kamo
Commit
872743e

Cilium egress is default-deny for every endpoint it selects, and toEndpoints:[{}] is scoped to the policy's OWN namespace — so SecurityService could not reach desktop-1-agent:9800 and reported the machine offline while it was healthy. The symptom is a connect timeout, not a refusal, so it reads as the far end being down. Also removes **************** it declared the SAME object as kamo-egress.yaml, so applying the directory made the two fight with alphabetical order deciding the winner. It was the stale copy — it still listed the retired CockroachDB port 26257. networkpolicies/ is now a CI apply target; it was applied by hand before, which is how that drift survived.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing