A packet capture of the config files would show something was up to anyone suspicious, but knowing what to do about it is a completely different story.
Of course, I have no non-circumstantial evidence and this could all be a coincidence, which is why my comment is prefixed with "conspiracy theory".
1: "However, he asked me to first look at their cluster of reverse gateways / load balancers"
2: Would have likely been less likely to find the issue with active analysis given the self destruct feature
3: "Specifically he wanted to know if I could develop a methodology for testing if an attacker has gained access to the gateways and is trying to access PII"
4: "I couldn't SSH into the host (no SSH), so I figured we will have to add some kind of instrumentation to the GO app. Klaus still insisted I start by looking at the traffic before (red) and after the GW (green)"
Perhaps they had noticed the programs restarting and when trying to debug triggered it.
The other ones could be explained by him being afraid of leaking PII, and most PII being on that system.
Not wanting to instrument the Go app could be an operational concern.
"Your <reverse gateway> devices are compromised and leak PII." Nothing more.
>I think he had some suspicions, but he is denying that vehemently ;)
https://twitter.com/IgorBog61650384/status/13753134251323146...