Network requirements¶
The design goal is simple: agents reach out, nothing reaches in. As a SaaS tenant your only real requirement is outbound HTTPS from the endpoints you enroll.
Agents — outbound only¶
BAS agents poll the platform outbound through NAT. They never open a listening port, so there are no inbound firewall rules, no port-forwards, and no VPN to set up.
| Direction | Protocol / Port | Destination | Purpose |
|---|---|---|---|
| Outbound | HTTPS 443 | the platform's agent endpoint (on j-huebner.com) |
register, poll for tasks, post results, upgrade checks |
| Outbound | DNS 53 | your resolver | resolve the endpoint hostname |
Requirements for the egress path:
- Allow HTTPS to the platform hostname. If you filter egress, allow-list the agent endpoint; a domain allow-list is enough.
- HTTP proxies are fine as long as they allow CONNECT to 443.
- TLS interception: if your proxy re-signs TLS, its CA must be trusted by the host so the agent can validate the connection.
- No static IP or inbound DNS is needed for the endpoint itself.
Console & API access¶
Operators reach the console over HTTPS 443, fronted by an identity-aware proxy: every request must carry a valid access assertion or it's refused at the edge before reaching the app. Sign-in is via your configured identity provider (see Configuration).
- Allow your operators' browsers outbound 443 to the console hostname.
- No client certificates or VPN required — identity is enforced at the proxy.
Self-host: internal connectivity¶
If you run your own deployment, these paths are internal and should not be exposed to the internet:
| Path | Protocol | Exposure |
|---|---|---|
| Control plane → inference node | HTTP (model API) | internal only |
| Control plane → executor | HTTP (sandbox API, bearer-authenticated) | internal only |
| Control plane → BAS server | HTTP (proxied by the app) | internal only |
| Ingress → control plane | HTTP behind the identity-aware proxy | only the proxy is public |
Executor egress¶
The executor's outbound reach is chosen per run and defaults to the safe mode:
| Sandbox mode | Egress |
|---|---|
isolated (default) |
internet only — cannot reach your LAN |
vpn |
the target range of an uploaded VPN profile |
lan |
full LAN — a deliberate, separately-gated bypass |
See the Safety model for how these modes are gated. Only enable
lan, and only allow the executor onto a segment, when you intend it.
Summary for a tenant
Allow outbound 443 + DNS from your endpoints to the platform on
j-huebner.com. Nothing inbound. That's the whole network requirement.