Last modified September 12, 2026

Domain allowlist

Giant Swarm clusters need outbound access to the external domains listed here to function. Use this page to configure your firewall, proxy, or egress policy.

How to read this page

Everything in the required domains, on-premise installations and Agent Platform tables is HTTP or HTTPS traffic over TCP on port 443, unless specified otherwise.

Two flows aren’t HTTP, so a conventional firewall can’t match them by hostname. They have their own section, non-HTTP traffic.

Because a wildcard never covers the domain it belongs to, every base domain we also need access to gets its own row next to its wildcard.

Required domains

DomainWhy we need it
alpinelinux.orgAlpine container images may update their package index.
*.alpinelinux.orgAlpine container images may update their package index.
amazonaws.comAWS services are used for a variety of tasks, such as etcd backup storage.
*.amazonaws.comAWS services are used for a variety of tasks, such as etcd backup storage.
azure.microsoft.comContainer images and app catalogs are hosted on the Azure container registry.
management.azure.comAzure API required by the Azure cloud controller manager.
blob.core.windows.netThe Azure container registry serves image layer blobs from Azure blob storage.
*.blob.core.windows.netThe Azure container registry serves image layer blobs from Azure blob storage.
giantswarm.azurecr.ioContainer images and app catalogs are hosted on the Azure container registry.
gsoci.azurecr.ioContainer images and app catalogs are hosted on the Azure container registry.
gsociprivate.azurecr.ioContainer images and app catalogs are hosted on the Azure container registry.
cloudfront.netOperators may pull from sites behind Cloudfront.
*.cloudfront.netOperators may pull from sites behind Cloudfront.
cronitor.ioCronitor’s API is used to ensure our alerting pipeline is fully functional (heartbeat monitoring).
cronitor.linkCronitor’s API is used to ensure our alerting pipeline is fully functional (heartbeat monitoring).
docker.comContainer images are hosted on Dockerhub, which uses Cloudflare as the CDN for serving image layer blobs, manifests, and more.
*.docker.comContainer images are hosted on Dockerhub, which uses Cloudflare as the CDN for serving image layer blobs, manifests, and more.
docker.ioContainer images are hosted on Dockerhub.
*.docker.ioContainer images are hosted on Dockerhub.
flatcar-linux.orgFlatcar OS images and signing keys.
*.flatcar-linux.orgFlatcar OS images and signing keys.
ghcr.ioOfficial Falco rules are hosted at ghcr.io/falcosecurity. Optional if you turn off the official rulesets or host them elsewhere.
github.comVarious operators need to pull information from GitHub repositories.
*.github.comVarious operators need to pull information from GitHub repositories.
github.ioHelm chart tarballs are pulled from GitHub Pages.
*.github.ioHelm chart tarballs are pulled from GitHub Pages.
pkg-containers.githubusercontent.comFalco optionally loads resources from this domain.
raw.githubusercontent.comFlux applies some manifests from this domain.
k8s.gcr.io(Legacy) Kubernetes container images are hosted on Google Container Registry.
schema.giantswarm.ioOur schema server hosts the schemas for container image validation.
teleport.giantswarm.ioUsed to securely access Kubernetes clusters and to get SSH access to nodes.
vault.operations.giantswarm.ioOur operations Vault is used for unsealing customer Vault servers.
storage.googleapis.comGoogle Container Registry is backed by a Google Cloud Storage bucket.
grafana.comGrafana may download plugins from the Grafana plugin registry.
grafana.netSome metrics are pushed to our hosted Grafana tenant.
*.grafana.netSome metrics are pushed to our hosted Grafana tenant.
grafana.orgSome metrics are pushed to our hosted Grafana tenant.
*.grafana.orgSome metrics are pushed to our hosted Grafana tenant.
registry.k8s.ioContainer registry and global CDN for the Kubernetes project’s container images.
api.letsencrypt.orgcert-manager requests certificates from Let’s Encrypt.
*.api.letsencrypt.orgcert-manager requests certificates from Let’s Encrypt.
graph.microsoft.comUsed when logging into the cluster with Microsoft AD.
login.microsoftonline.comUsed when logging into the cluster with Microsoft AD.
events.eu.pagerduty.comPagerDuty’s API is used to send alerts.
quay.ioContainer images are hosted on Quay.
*.quay.ioContainer images are hosted on Quay.
o346224.ingest.sentry.ioMonitoring and crash reporting for happa.
sigstore.devUsed to verify signatures on artifacts signed with the cosign keyless signing method.
*.sigstore.devUsed to verify signatures on artifacts signed with the cosign keyless signing method.
slack.comUsed to send alerts to Slack channels.
*.slack.comUsed to send alerts to Slack channels.
xpkg.upbound.ioUsed to fetch Crossplane packages.

On-premise installations

These domains are only required for on-premise installations. They’re HTTP or HTTPS traffic, like the required domains.

DomainWhy we need it
api.cloudflare.comcert-manager may create ACME challenge DNS records.

Agent Platform

The Agent Platform is an opt-in addition to a management cluster. Its own components need nothing beyond the required domains: images and charts come from the Giant Swarm registry and agent skills from GitHub. What it adds is the model provider you choose for your agents. The platform ships without a model credential and without a preferred provider, so which of these domains you need depends on the provider you bring, as described in Bring your own model.

DomainWhy we need it
api.anthropic.comModel configurations for Anthropic models.
api.openai.comModel configurations for OpenAI models.
*.openai.azure.comModel configurations for Azure OpenAI. Permit the endpoint of your own Azure OpenAI resource instead of the wildcard if you prefer.
*.cognitiveservices.azure.comAzure OpenAI resources created as Azure AI Foundry or Azure AI Services resources are served from this domain.
generativelanguage.googleapis.comModel configurations for Google Gemini models.
huggingface.coOptional. Pulling model weights from the Hugging Face Hub when the installation serves models itself. Weights from any other source need no Hugging Face access.
*.huggingface.coOptional. Pulling model weights from the Hugging Face Hub when the installation serves models itself. Weights from any other source need no Hugging Face access.
hf.coOptional. The Hugging Face Hub serves weights from this domain.
*.hf.coOptional. The Hugging Face Hub serves weights from this domain.

Amazon Bedrock is served from *.amazonaws.com, which is already a required domain. A model endpoint you host inside your own network needs no public egress at all.

A firewall that blocks the provider doesn’t show up as a firewall error: the model configuration is accepted, the agent starts, and every request fails with a connection reset. See the troubleshooting section of the model guide.

Non-HTTP traffic

Clusters open two kinds of connection that don’t carry an HTTP request, so there’s no hostname for a proxy to read and match. Handle them like this:

  • If your firewall can resolve and match hostnames itself on non-HTTP traffic, put the hostnames below on the allowlist, exactly as you would for an HTTP domain.
  • If it can’t, use the fallback described for each flow.

SSH to ssh.github.com

HostnamePortProtocol
ssh.github.com443SSH over TCP

Fallback: We can tunnel this connection through the HTTP proxy with a CONNECT request to ssh.github.com:443. Apply the following patches to Flux’s Source Controller:

- op: add
  path: "/spec/template/spec/hostAliases/-"
  value:
    ip: "127.0.0.1"
    hostnames:
      - "ssh.github.com"
- op: add
  path: "/spec/template/spec/containers/-"
  value:
    name: proxy
    image: gsoci.azurecr.io/giantswarm/socat:1.7.4.4
    securityContext:
      allowPrivilegeEscalation: false
      readOnlyRootFilesystem: true
      runAsUser: 100
    command:
      - /bin/sh
      - -c
      - |
        # Fallback to static argument if injected env var doesn't exist
        export HTTP_PROXY=$${HTTP_PROXY:=${proxy_hostname}:${proxy_port}}

        export PROXY_HOSTNAME=$(echo $${HTTP_PROXY#http://} | cut -d":" -f1)
        export PROXY_PORT=$(echo $${HTTP_PROXY#http://} | cut -d":" -f2)

        socat TCP4-LISTEN:8081,fork,reuseaddr PROXY:$${PROXY_HOSTNAME}:ssh.github.com:443,proxyport=$${PROXY_PORT}

NTP time synchronization

HostnamePortProtocol
0.flatcar.pool.ntp.org123NTP over UDP
1.flatcar.pool.ntp.org123NTP over UDP
2.flatcar.pool.ntp.org123NTP over UDP
3.flatcar.pool.ntp.org123NTP over UDP

Flatcar nodes synchronize their clock with the Flatcar NTP pool by default. Each pool.ntp.org hostname resolves to a rotating set of servers, so don’t translate these names into static IP rules, which go stale.

Fallback: permit all outbound NTP traffic on port 123. If that’s too broad for your policy, point the nodes at an NTP server you run yourself, through the cluster app’s timesyncd values, and restrict egress to that server.