Match the process name
An exemption list of file names is bypassed by renaming your own program. That is how egress control failed on Yunshu 2.5.12.16. This agent does not read the process name or the PID.
Zero trust access · egress denied by default
The agent checks Team ID, Signing ID, cdhash, domain, and port together. A full path in the rule must match the entire path, and a path without a cdhash is not loaded. After the single packet checks out, the access point dials only the upstream stored in the console.
// one agent · signature and hash · rules in the console · upstream address stays out of the packet
The gap
An exemption list of file names is bypassed by renaming your own program. That is how egress control failed on Yunshu 2.5.12.16. This agent does not read the process name or the PID.
fwknop inserts a temporary allow for the source address. Many people share that address behind NAT, and the upstream is then reachable directly. Our packet mints a grant. It does not add a firewall rule toward the upstream.
Once the subnet is yours, the neighboring hosts are scannable. There is no virtual NIC here. The access point dials the one upstream written in the console.
Three steps
The console runs on Cloudflare Workers. Rules sit in D1. Each write publishes a snapshot to R2 at snapshots/current.json.
The system extension reads Team ID, Signing ID, cdhash, and the full path from the audit token, then asks the local Go process. No answer within 300 ms means deny, not a direct connection.
The UDP packet is AES-256-GCM. A bad tag is dropped with no reply. The TLS session must still prove the ephemeral key. An address carried in the session is ignored.
Compare
| Capability | Process name | Source-IP hole | Full VPN | zerotrust.supply |
|---|---|---|---|---|
| Team ID, Signing ID, cdhash | – | – | – | Yes |
| Full path only together with cdhash | – | – | – | Yes |
| Failed packet gets no reply | – | Yes | – | Yes |
| No upstream allow by source address | – | – | – | Yes |
| Dial only a registered upstream | – | – | – | Yes |
| Execution allowlist | – | – | – | Not built. Endpoint Security needs a separate Apple grant. |
The system extension is not installed on a Mac yet. We have not measured whether a closed port answers a scan on Linux, so this page does not claim that. UDP applications and QUIC are not forwarded in this version.
console
Sign in with the demo account to see them. With no rule, egress is denied.
Open the console