Network and firewall
← Back to Index | Previous: Post-install configuration | Next: Troubleshooting →
9.1 Overview
This chapter lists destinations and ports for enterprise Deslicer AI and DAP installs. Unless noted, registry and package traffic uses HTTPS on port 443.
Allowlists apply to both the DAI host and the DAP host unless a row says otherwise. Product hostnames in commands mean:
| Placeholder | Meaning |
|---|---|
<dai-host> | DAI public FQDN |
<dap-host> | DAP public FQDN |
| Deslicer / OS destinations below | Leave hostnames as written (do not replace with your DAI/DAP FQDN) |
9.2 Outbound allowlist — Deslicer registries
| Destination | Purpose |
|---|---|
artifact-registry.deslicer.io | Install scripts and packages |
container-registry.deslicer.io | Docker/OCI image pulls |
package-registry.deslicer.io | Package repository channels when used |
nexus-registry.deslicer.io | Nexus admin / REST when required |
registry.deslicer.io | Registry metadata API |
If your engagement uses an alternate or regional registry hostname, Deslicer lists it in the handoff—add those destinations as well.
9.3 Outbound allowlist — OS packages, Docker, and installer tooling
Curl installers bootstrap a local Ansible environment and install missing OS packages (Python 3.13, curl, acl/setfacl, Docker/Compose, and related dependencies). Ansible content is vendored inside the Deslicer install packages — you do not need outbound access to Ansible Galaxy for the primary path. You do need outbound access from both product hosts to the package sources your OS uses (or an internal mirror that proxies them).
| Family | Typical destinations to allow (or mirror) | Why |
|---|---|---|
| Ubuntu / Debian | Distro apt mirrors (for example archive.ubuntu.com, security.ubuntu.com, or your corporate mirror) | apt-get packages during prep / install |
| RHEL / Rocky / Alma / Oracle | BaseOS, AppStream, CRB / CodeReady Builder, and EPEL (Fedora epel-release / EPEL mirror as used by the installer) | Python 3.13 and related RPMs |
| RHEL-family Docker CE | Docker CE yum/dnf repository for your major version (installer-managed; not get.docker.com as a manual step) | docker-ce / Compose plugin |
| Amazon Linux 2023 | Amazon Linux repos (dnf / AL2023 mirrors) | Distro packages; leave curl-minimal alone |
| age CLI (RHEL-family / AL2023 path) | dl.filippo.io | Official age binary download when not using apt age |
| Optional IdP / SMTP / LLM | Your IdP issuer, SMTP relay, and BYOK LLM provider API hostnames | Auth, mail, and model traffic after install |
Air-gapped or tightly filtered networks should pre-stage equivalent mirrors and confirm with Deslicer which destinations your engagement still needs online (at minimum container/artifact registry access unless images are imported offline).
ACME (automatic HTTPS)
When using ACME on a product host, allow outbound HTTPS to your certificate authority (for Let’s Encrypt, the public ACME endpoints). That host must also accept inbound HTTP 80 for HTTP-01 challenges unless you use a DNS challenge mode Deslicer configured for you.
9.4 Inbound ports
DAI host
| Port | Direction | Purpose |
|---|---|---|
| 443/tcp | Inbound | Public HTTPS via Deslicer Caddy (https://<dai-host>/) |
| 80/tcp | Inbound | ACME HTTP-01 (when using automatic HTTPS) |
Do not expose 13000 or 13001 on the public interface.
DAP host
| Port | Direction | Purpose |
|---|---|---|
| 443/tcp | Inbound | Observer API edge (Deslicer Caddy) on https://<dap-host>/ |
| 8443/tcp | Inbound | Observer UI edge (Deslicer Caddy) on https://<dap-host>:8443 |
| 80/tcp | Inbound | ACME HTTP-01 when using automatic HTTPS |
Always open the ports Control shows for your backend—not only this table.
9.5 Host-to-host and Splunk paths
| Source | Destination | Purpose |
|---|---|---|
| DAI host | DAP Observer URL (https://<dap-host>/ on 443) | Deslicer AI → Observer API integration |
| Operator workstations | DAI :443, DAP :443 / :8443 | Control, app UI, Observer UI |
| Splunk / worker hosts | DAP Observer URL (:443) | Later enrollment (after platform install) |
| DAI host | Customer Splunk management API | Agent tools (splunk-mcp → 8089 HTTPS) |
| DAP host | Customer Splunk management API | Plan execution / host ops (8089 HTTPS) |
9.6 Proxies
If the DAI host or DAP host must use an HTTP CONNECT proxy for outbound HTTPS:
- Configure Docker and the OS trust store per your standard
- Ensure the proxy allows the Deslicer registry destinations and the OS package destinations in §9.3
- ACME HTTP-01 still needs a public path to port 80 on the product host (or a DNS challenge)
← Back to Index | Previous: Post-install configuration | Next: Troubleshooting →