> The main challenge is to find a flow to signal to kloak what to rewrite and how to inject kloaked secrets to the workload
Would it be realistic or reasonable to detect a header like `X-kloak-ENABLED` or specific endpoints in the case of HTTP?
Similar for wire protocols like PostgreSQL or gRPC?
Our would a usermode proxy be easier but not preferred due to overhead?