Skip to content

Optional Squid backend as an alternate HTTP egress data plane (deploy/squid/) #45

Description

@amondnet

Context

Roadmap cross-cutting (docs/roadmap.md), explicitly optional: a deploy/squid/ configuration offering Squid as an alternate HTTP egress backend (domain allowlisting via generated ACLs) for environments that already operate Squid, or where the Rust data plane can't run.

Tasks

  • Generate Squid ACL config from a honmoon policy's egress lists (subset: domain allow/deny only — no CEL, no protocol facts, no PII; document the gap)
  • deploy/squid/ with container setup + docs
  • Decide whether audit events can be bridged (Squid access log → @honmoon/api ingestion) or are out of scope

Priority: p3 — optional alternative path; the native data plane is the product.
Effort: M — config generation + deployment docs, but a strictly bounded feature subset.

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort:MMedium — 1–3 daysp3Priority 3 - Lowtype:featureNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions