hmm wonder if it would be funny to have a Security thing where the control plane nodes are in a different subnet than the worker nodes
@littlefox ah yeah I wanna make the control plane nodes properly control plane, no actual workloads running
@littlefox well I'd basically allow cp <-> worker, worker <->internet, cp -> internet, but no internet -> cp is my plan