Thanks. Like you, I'd been running containers inside VMs for a while before the agents. Turns out it's right for them too. Making it IPv4-only simplified the firewall rules and network containment check, and made the boundary easier to reason about.
No comments yet.