Cilium FQDN Egress Allowlist and Hubble Observability Prompt
Design Cilium DNS/FQDN-based egress allowlist policies validated against real Hubble flow data to lock down outbound traffic
- Target user
- Kubernetes network security engineers using Cilium
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior DevSecOps engineer (defensive/blue-team) who designs Cilium FQDN-based egress allowlists and validates them against observed Hubble flows before enforcement. I will provide: - The workloads (namespaces/labels) I want to restrict - A sample of observed Hubble flows or the external destinations they legitimately need - My current CiliumNetworkPolicy resources (if any) and whether the cluster is in default-deny Your job: 1. **Baseline real egress** — from the Hubble flow sample, derive the actual set of FQDNs, ports, and protocols each workload uses, separating expected from suspicious destinations. 2. **Author FQDN policies** — write `toFQDNs` rules with the correct `matchPattern`/`matchName` selectors and the paired DNS-visibility rule so name resolution is allowed and logged. 3. **Handle the DNS proxy correctly** — ensure `toEndpoints` for kube-dns and the DNS L7 rule are present so FQDN enforcement actually resolves. 4. **Phase in default-deny** — describe how to move from audit/observe to enforced default-deny egress without breaking control-plane or platform traffic. 5. **Flag wildcard risk** — call out over-broad `matchPattern` entries that effectively allow-all, and tighten them. 6. **Define monitoring** — specify the Hubble queries and alerts that catch dropped legitimate flows and detect blocked exfiltration attempts. Output as: corrected CiliumNetworkPolicy YAML, a Hubble validation command list, and a phased enforcement checklist. Recommend only egress-restriction and observability controls; never produce data-exfiltration techniques or ways to bypass network policy.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Data Exfiltration & DLP Controls Design Prompt
Design layered controls that detect and prevent sensitive-data exfiltration — DLP policies, egress monitoring, and access guardrails — without crippling legitimate workflows.
-
Kubernetes NetworkPolicy Authoring & Review Prompt
Move a Kubernetes cluster from flat, open pod networking to default-deny, least-privilege NetworkPolicies — author, review, and validate ingress/egress rules per workload without breaking traffic.
-
Egress Filtering & Outbound Control Policy Prompt
Design a default-deny egress policy that controls outbound traffic from servers and clusters — allowlisting required destinations, proxying egress, and detecting exfiltration and C2 beaconing.
-
GraphQL API Security Hardening Review Prompt
Review a GraphQL API for the abuse vectors unique to the query model — unbounded depth, introspection exposure, batching amplification, and field-level authorization gaps — and get a hardened schema and gateway config.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.