The kubectl_api ACL allowed CONNECT tunnels to any host on port 6443, bypassing the domain allowlist entirely. Remove it and require cluster hostnames to be added explicitly to allowed_sites instead. Also remove the localhost and .local entries — these aren't needed for Claude Code or the configured MCP servers. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Dockerfile | ||
| squid.conf | ||