Skip to main content

Network and firewall

← Back to Index | Previous: Post-install configuration | Next: Troubleshooting →


9.1 Overview​

This chapter lists destinations and ports for enterprise Deslicer AI and DAP installs. Unless noted, registry and package traffic uses HTTPS on port 443.

Allowlists apply to both the DAI host and the DAP host unless a row says otherwise. Product hostnames in commands mean:

PlaceholderMeaning
<dai-host>DAI public FQDN
<dap-host>DAP public FQDN
Deslicer / OS destinations belowLeave hostnames as written (do not replace with your DAI/DAP FQDN)

9.2 Outbound allowlist — Deslicer registries​

DestinationPurpose
artifact-registry.deslicer.ioInstall scripts and packages
container-registry.deslicer.ioDocker/OCI image pulls
package-registry.deslicer.ioPackage repository channels when used
nexus-registry.deslicer.ioNexus admin / REST when required
registry.deslicer.ioRegistry metadata API

If your engagement uses an alternate or regional registry hostname, Deslicer lists it in the handoff—add those destinations as well.

9.3 Outbound allowlist — OS packages, Docker, and installer tooling​

Curl installers bootstrap a local Ansible environment and install missing OS packages (Python 3.13, curl, acl/setfacl, Docker/Compose, and related dependencies). Ansible content is vendored inside the Deslicer install packages — you do not need outbound access to Ansible Galaxy for the primary path. You do need outbound access from both product hosts to the package sources your OS uses (or an internal mirror that proxies them).

FamilyTypical destinations to allow (or mirror)Why
Ubuntu / DebianDistro apt mirrors (for example archive.ubuntu.com, security.ubuntu.com, or your corporate mirror)apt-get packages during prep / install
RHEL / Rocky / Alma / OracleBaseOS, AppStream, CRB / CodeReady Builder, and EPEL (Fedora epel-release / EPEL mirror as used by the installer)Python 3.13 and related RPMs
RHEL-family Docker CEDocker CE yum/dnf repository for your major version (installer-managed; not get.docker.com as a manual step)docker-ce / Compose plugin
Amazon Linux 2023Amazon Linux repos (dnf / AL2023 mirrors)Distro packages; leave curl-minimal alone
age CLI (RHEL-family / AL2023 path)dl.filippo.ioOfficial age binary download when not using apt age
Optional IdP / SMTP / LLMYour IdP issuer, SMTP relay, and BYOK LLM provider API hostnamesAuth, mail, and model traffic after install

Air-gapped or tightly filtered networks should pre-stage equivalent mirrors and confirm with Deslicer which destinations your engagement still needs online (at minimum container/artifact registry access unless images are imported offline).

ACME (automatic HTTPS)​

When using ACME on a product host, allow outbound HTTPS to your certificate authority (for Let’s Encrypt, the public ACME endpoints). That host must also accept inbound HTTP 80 for HTTP-01 challenges unless you use a DNS challenge mode Deslicer configured for you.

9.4 Inbound ports​

DAI host​

PortDirectionPurpose
443/tcpInboundPublic HTTPS via Deslicer Caddy (https://<dai-host>/)
80/tcpInboundACME HTTP-01 (when using automatic HTTPS)

Do not expose 13000 or 13001 on the public interface.

DAP host​

PortDirectionPurpose
443/tcpInboundObserver API edge (Deslicer Caddy) on https://<dap-host>/
8443/tcpInboundObserver UI edge (Deslicer Caddy) on https://<dap-host>:8443
80/tcpInboundACME HTTP-01 when using automatic HTTPS

Always open the ports Control shows for your backend—not only this table.

9.5 Host-to-host and Splunk paths​

SourceDestinationPurpose
DAI hostDAP Observer URL (https://<dap-host>/ on 443)Deslicer AI → Observer API integration
Operator workstationsDAI :443, DAP :443 / :8443Control, app UI, Observer UI
Splunk / worker hostsDAP Observer URL (:443)Later enrollment (after platform install)
DAI hostCustomer Splunk management APIAgent tools (splunk-mcp → 8089 HTTPS)
DAP hostCustomer Splunk management APIPlan execution / host ops (8089 HTTPS)

9.6 Proxies​

If the DAI host or DAP host must use an HTTP CONNECT proxy for outbound HTTPS:

  • Configure Docker and the OS trust store per your standard
  • Ensure the proxy allows the Deslicer registry destinations and the OS package destinations in §9.3
  • ACME HTTP-01 still needs a public path to port 80 on the product host (or a DNS challenge)

← Back to Index | Previous: Post-install configuration | Next: Troubleshooting →