Last modified October 3, 2025
Domain allowlist
List of the external domains we require access to for our clusters to function.
alpinelinux.org- domains:
*.alpinelinux.org
- Alpine container images may update their package index.
- domains:
amazonaws.com- domains:
*.amazonaws.com
- AWS services are used for a variety of tasks, such as
etcdbackup storage.
- domains:
azurecr.io- domains:
giantswarm.azurecr.iogiantswarmpublic.azurecr.iogsoci.azurecr.iogsociprivate.azurecr.io.blob.core.windows.netazure.microsoft.com
- Container images and app catalogs are hosted on Azure container registry.
- domains:
cloudfront.net- domains:
*.cloudfront.net
- Operators may pull from sites behind
Cloudfront.
- domains:
docker.com- domains:
*.docker.com
- Container images are hosted on
Dockerhub. DockerhubusesCloudflareas theCDNfor serving Docker image layer blobs, manifests, etc.
- domains:
docker.io- domains:
*.docker.io
- Container images are hosted on
Dockerhub.
- domains:
flatcar.com- domains:
*.flatcar-linux.org
- Flatcar OS images and signing keys.
- domains:
ghcr.io- domains:
ghcr.io
- Official
Falcorules are hosted atghcr.io/falcosecurity. This domain is optional if official rulesets are disabled or hosted elsewhere.
- domains:
github.com- domains:
*.github.com
- Various operators need to pull information from GitHub repositories.
- domains:
github.io- domains:
*.github.io
- Helm chart tarballs are pulled from GitHub Pages.
- domains:
githubusercontent.com- domains:
raw.githubusercontent.compkg-containers.githubusercontent.com
Fluxapplies some manifests using the raw domain.Falcooptionally loads resources from the pkg-containers domain.
- domains:
gcr.io- domains:
k8s.gcr.io
- (Legacy) k8s container images are hosted on Google Container Registry.
- domains:
googleapis.com- domains:
storage.googleapis.com
- Google container registry is backed by a Google cloud storage bucket.
- domains:
grafana.com- domains:
grafana.com
- Grafana may download plugins from the Grafana plugin registry.
- domains:
grafana.net- domains:
*.grafana.net*.grafana.org
- Some metrics are pushed to our hosted Grafana tenant.
- domains:
giantswarm.io- domains:
vault.operations.giantswarm.ioschema.giantswarm.io
- Our operations Vault is used for unsealing customer Vault servers.
- Our schema server hosts the schemas for container image validation.
- domains:
k8s.io- domains:
registry.k8s.io
- Container registry and a global
CDNfor the k8s project’s container images.
- domains:
keybase.io- domains:
*.keybase.io
- Vault initialization and unsealing requires access to
Keybase.
- domains:
letsencrypt.org- domains:
*.api.letsencrypt.org
- cert-manager will request certificates from Lets Encrypt.
- domains:
microsoft.com- domains:
graph.microsoft.com
- Used when logging into the cluster with Microsoft AD.
- domains:
microsoftonline.com- domains:
login.microsoftonline.com
- Used when logging into the cluster with Microsoft AD.
- domains:
opsgenie.com- domains:
api.opsgenie.com
- Opsgenie’s API is used to send alerts.
- domains:
pagerduty.com- domains:
api.eu.pagerduty.com
- PagerDuty’s API is used to send alerts.
- domains:
quay.io- domains:
*.quay.io
- Container images are hosted on Quay.
- domains:
sentry.io- domains:
o346224.ingest.sentry.io
- Monitoring and crash reporting for
happa.
- domains:
sigstore.dev- domains:
*.sigstore.dev
- Used for verifying signatures on artifacts signed with the cosign keyless signing method.
- domains:
slack.com- domains:
*.slack.com
- Used to send alerts on slack channels
- domains:
teleport.giantswarm.io- domains:
teleport.giantswarm.io
- Used to securely access Kubernetes cluster and SSH access to nodes.
- domains:
xpkg.upbound.io- domains:
xpkg.upbound.io
- Used to fetch
Crossplanepackages.
- domains:
On-premise installations
These domains are only required for on-premise installations.
cloudflare.com- domains:
api.cloudflare.com
- cert-manager may create ACME challenge DNS records.
- domains:
Need help, got feedback?
We listen to your Slack support channel. You can also reach us at support@giantswarm.io. And of course, we welcome your pull requests!