-
Notifications
You must be signed in to change notification settings - Fork 1.2k
feat(network): enable Docker and Podman policy DNS and transparent TCP #2723
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
johntmyers
merged 32 commits into
main
from
feat/2712-docker-transparent-tcp/johntmyers
Aug 20, 2026
Merged
Changes from all commits
Commits
Show all changes
32 commits
Select commit
Hold shift + click to select a range
961e456
feat(network): enable Docker transparent TCP egress
johntmyers c54dcfe
test(e2e): cover Docker transparent TCP egress
johntmyers cc37086
feat(network): correlate transparent TCP audit events
johntmyers e2bc255
docs(examples): add transparent TCP Redis demo
johntmyers fd772ad
docs(examples): demonstrate blocked TCP connections
johntmyers 670b0a2
docs(examples): focus Redis demo audit output
johntmyers bc8406b
fix(network): close transparent TCP policy bypasses
johntmyers a721e91
fix(sandbox): reject unsupported TCP policy reloads
johntmyers 38622f0
fix(ci): satisfy Linux transparent TCP lints
johntmyers 08c6ee2
feat(podman): enable transparent TCP egress
johntmyers d5a0e9b
fix(podman): permit policy DNS port binding
johntmyers be54bce
test(e2e): use qualified transparent TCP hostname
johntmyers 8cfcf93
fix(podman): preserve exact policy DNS names
johntmyers e95e1fa
fix(podman): route policy DNS over TCP
johntmyers 72d91de
fix(dns): serve multiple TCP queries per connection
johntmyers 00707bd
docs(network): explain native DNS and TCP egress
johntmyers 85eaf7e
fix(sandbox): reconcile runtime reload with upstream
johntmyers 70c1bfd
fix(network): harden transparent DNS capture
johntmyers 5779cab
fix(podman): preserve resolver behavior for native tcp
johntmyers cee830a
docs(network): clarify native tcp runtime constraints
johntmyers b400b94
fix(network): remove unused transparent tcp pin
johntmyers e76f032
fix(network): admit redirected transparent tcp
johntmyers 5d7d7f5
fix(network): restore podman transparent networking
johntmyers 03137c6
test(podman): permit alpine busybox binaries
johntmyers ec1be61
test(podman): use portable alpine keepalive
johntmyers 0140736
test(podman): build musl networking fixture
johntmyers c84e74e
test(podman): isolate musl DNS probe
johntmyers 96305ed
fix(podman): keep privileged port capability dropped
johntmyers 044e22f
fix(network): preserve transparent TCP port 53
johntmyers eac8cdd
fix(network): report synthetic pool pressure by family
johntmyers aa8d4b8
test(podman): bind tcp fixtures before readiness
johntmyers bbffdb4
test(podman): grant fixture low-port bind
johntmyers File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.