Skip to content

Optional Squid backend as an alternate HTTP egress data plane (deploy/squid/) #45

Description

@amondnet

Context

Roadmap cross-cutting (docs/roadmap.md), explicitly optional: a deploy/squid/ configuration offering Squid as an alternate HTTP egress backend (domain allowlisting via generated ACLs) for environments that already operate Squid, or where the Rust data plane can't run.

Tasks

  • Generate Squid ACL config from a honmoon policy's egress lists (subset: domain allow/deny only — no CEL, no protocol facts, no PII; document the gap)
  • deploy/squid/ with container setup + docs
  • Decide whether audit events can be bridged (Squid access log → @honmoon/api ingestion) or are out of scope

Priority: p3 — optional alternative path; the native data plane is the product.
Effort: M — config generation + deployment docs, but a strictly bounded feature subset.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions