How to connect Namespaces over ingress/egress gateways only?

From the security perspective we need to support SDS on the egress gateway. With that in place both ingress and egress gateway certificate management would be handled uniformly.