Cloud Security Podcast

"Escape-Proof" Cloud: How Block built an Automated Approach to Egress Control

Jul 1, 2025
Ramesh Ramani, a Staff Security Engineer at Block, specializes in cloud security with a solid background in network engineering. In this discussion, he highlights how organizations can improve data security by focusing on egress control. Ramesh introduces an innovative automated system that centralizes governance for outbound access, streamlining security and compliance with SPIFFE IDs. He also emphasizes the importance of a phased approach in enhancing egress control and improving incident response, ensuring organizations can swiftly manage third-party access and data protection.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Egress Controls Are Critical

  • Egress control is overlooked compared to ingress but is critical once attackers bypass ingress.
  • Attackers can't steal data if they can't exit, making egress control essential for security.
ANECDOTE

Automating Egress from Kubernetes

  • Ramesh helped build Block's first Kubernetes security platform using an automated network policy application.
  • This inspired expanding automation to all egress access at Block, bridging existing sources of truth.
INSIGHT

Challenges of Application Identification

  • Identifying applications across varied cloud and data center environments is complex for egress control.
  • Manual GitOps-style egress access requests don't scale well in large, diverse cloud environments.
Get the Snipd Podcast app to discover more snips from this episode
Get the app