For agent workloads, how are you separating "where the code runs" (namespace/gVisor/microVM) from "what credentials and egress ever enter that guest"?