needs some networkpolicies. in/out from envoy-gateway-system? in/out from envoy-ai-gateway-system? in/out from other workloads on the same cluster.... how to manage this?