#general

Aug 26September 4, 2026
M
matthew.gregor2:40 AMOpen in Slack
With github.com/archestra-ai/archestra/pull/6488 was the intention on this to hard block all access to the following ranges from MCP pods with no way to override if the environments networkPolicy is set to unrestricted (Allow All)?:
- 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 - RFC 1918 private ranges (cluster pods, services, nodes) <--- This is the primary one I'm wondering about
- 169.254.0.0/16 - Link-local / cloud metadata endpoints (AWS IMDSv1, GCP, Azure)
  • 168.63.129.16/32 - Azure platform metadata (a public IP outside the private ranges)
- 100.64.0.0/10 - Carrier-grade NAT (RFC 6598)
-- 127.0.0.0/8 - Loopback
-- 0.0.0.0/32 - Treated as localhost by some HTTP libraries
13 replies

Read-only live mirror of Archestra.AI Slack

👋Join the discussion withAI enthusiasts!