Skip to content

feat(zero-trust-assessment): add private app connector fail-open gates#2769

Closed
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:feat/private-app-connector-failopen-gates
Closed

feat(zero-trust-assessment): add private app connector fail-open gates#2769
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:feat/private-app-connector-failopen-gates

Conversation

@zeroknowledge0x

Copy link
Copy Markdown

Closes #2767

Follows the issue-first policy. Issue #2767 documents this skill.

Previous PRs (#2762, #2764, #2766) were auto-closed by needs-approved-issue policy. Re-raised now that #2767 exists.

- Add ZT-NET-12 through ZT-NET-16 findings for connector fail-open gaps
- Add Private App Connector Fail-Open Readiness Assessment section (6 factors)

Addresses UnitOneAI#2744: ZTNA designs that silently route around connectors, fall back
to VPN, or leave internal apps reachable from trusted networks violate zero trust.
New gates verify fail-closed behavior, policy sync, DNS enforcement, bypass
governance, direct route testing, and audit trail.
@github-actions github-actions Bot added the needs-approved-issue PR has no linked maintainer-approved issue label Jun 22, 2026
@github-actions

Copy link
Copy Markdown

Thanks for the submission! 🙏 SecuritySkills is now issue-first: contributions need a linked issue that a maintainer has marked approved before a PR is opened.

Please open an issue describing the skill, wait for the approved label, then reopen this PR with Closes #<issue> in the description. The PR template lists everything we'll look for (including an independently runnable reproduction).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-approved-issue PR has no linked maintainer-approved issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add ZT-NET fail-open gates for private app connectors

1 participant