User outcome
An address stops inheriting permission after its DNS association expires; lookup order does not unpredictably change access.
Current behavior
The ingress snooper learns A records into a per-pod LRU map. Associations do not expire by TTL and the last name learned for a shared address wins. See runtimepolicy.md, Limits of domain names.
Scope
- Design bounded name/address associations with TTL expiry and deterministic allow/deny conflict rules.
- Define policy deletion, re-resolution, CNAME, zero TTL, eviction, and restart semantics.
- Keep enforcement and reported attribution consistent; explicitly retain DNS visibility limits.
Acceptance
- Injected-time tests show an expired allowed address is blocked under default deny and renewed records refresh permission.
- Reversing DNS answer order for two names sharing an IP produces the same documented verdict.
- Capacity losses are counted and policy programming failures are visible.
- Kind checks cover rotation and a shared-IP conflict; no claim of encrypted-host identity enforcement.
Dependencies and boundaries
Needed before shipping wildcard-domain enforcement as reliable dynamic allowlisting. Exact-address proxy routing does not depend on this.
Validation and completion
- Table-driven tests pin the stated invariant, including invalid input and policy updates.
- For code changes:
make build and make test; significant changes also require make kind-install and a targeted behavioral check. Pipeline, collector, evaluator, or reporter changes require make smoke-quickstart.
- Kernel changes use the pinned BPF builder, generated-artifact verification, verifier loading, and allowed/denied behavior tests on supported hook paths.
- Update DESIGN, development guidance where affected, and the RuntimePolicy reference and limits. Every rejected user rule must reach an operator log and policy condition; count every observation drop. Preserve the reporter redaction boundary.
User outcome
An address stops inheriting permission after its DNS association expires; lookup order does not unpredictably change access.
Current behavior
The ingress snooper learns A records into a per-pod LRU map. Associations do not expire by TTL and the last name learned for a shared address wins. See runtimepolicy.md, Limits of domain names.
Scope
Acceptance
Dependencies and boundaries
Needed before shipping wildcard-domain enforcement as reliable dynamic allowlisting. Exact-address proxy routing does not depend on this.
Validation and completion
make buildandmake test; significant changes also requiremake kind-installand a targeted behavioral check. Pipeline, collector, evaluator, or reporter changes requiremake smoke-quickstart.