Skip to content

feat(zero-trust-assessment): add private app connector fail-open gates#2766

Closed
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:feat/private-app-connector-failopen-gates
Closed

feat(zero-trust-assessment): add private app connector fail-open gates#2766
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:feat/private-app-connector-failopen-gates

Conversation

@zeroknowledge0x

@zeroknowledge0x zeroknowledge0x commented Jun 22, 2026

Copy link
Copy Markdown

Closes #2767

Follows the issue-first policy now that #2767 documents this skill.

If the policy requires the issue to carry the approved label before a PR can stay open, please add that label to #2767 — happy to close again and wait.

- Add ZT-NET-12 through ZT-NET-16 findings for connector fail-open gaps
- Add Private App Connector Fail-Open Readiness Assessment section (6 factors)

Addresses UnitOneAI#2744: ZTNA designs that silently route around connectors, fall back
to VPN, or leave internal apps reachable from trusted networks violate zero trust.
New gates verify fail-closed behavior, policy sync, DNS enforcement, bypass
governance, direct route testing, and audit trail.
@github-actions

Copy link
Copy Markdown

Thanks for the submission! 🙏 SecuritySkills is now issue-first: contributions need a linked issue that a maintainer has marked approved before a PR is opened.

Please open an issue describing the skill, wait for the approved label, then reopen this PR with Closes #<issue> in the description. The PR template lists everything we'll look for (including an independently runnable reproduction).

@github-actions github-actions Bot added the needs-approved-issue PR has no linked maintainer-approved issue label Jun 22, 2026
@github-actions github-actions Bot closed this Jun 22, 2026
@zeroknowledge0x

Copy link
Copy Markdown
Author

Reopened to add Closes #2767 per issue-first policy

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-approved-issue PR has no linked maintainer-approved issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add ZT-NET fail-open gates for private app connectors

1 participant