Merge "Further lock down access to services from ephemeral apps" into oc-dev