Firewall Configuration

Introduction

If your environment uses a firewall or proxy that restricts outbound traffic, you must allow access to the external services listed below. These services are required for installation, runtime operations, and vulnerability data updates.

The specific configuration steps will vary depending on your firewall solution. Work with your network administrator to ensure the domains listed below are accessible over HTTPS (TCP 443) from your Manifest deployment.


Required External Services

Container Registries

These registries are required during installation and upgrades to pull container images.

DomainPurpose
623542229617.dkr.ecr.us-east-1.amazonaws.comManifest container images
quay.ioThird-party container images
docker.ioThird-party container images
registry.k8s.ioKubernetes container images

Installation Tools

Required during initial installation and upgrades.

DomainPurpose
get.helm.shHelm package manager

Vulnerability Data Sources

These services are accessed at runtime to retrieve and update vulnerability data. If these are blocked, vulnerability information will not be updated automatically.

DomainPurpose
nvd.nist.govNVD vulnerability database
services.nvd.nist.govNVD API endpoint
osv-vulnerabilities.storage.googleapis.comOSV vulnerability data
www.cisa.govCISA Known Exploited Vulnerabilities (KEV)
epss.cyentia.comEPSS exploit prediction scores
epss.empiricalsecurity.comEPSS exploit prediction scores
ecosyste.msOpen source package metadata

Optional Services

AI Risk Product

If your organization is subscribed to the AI Risk product, the following additional services must be accessible.

DomainPurpose
huggingface.coHugging Face API
api.openai.comOpenAI API
export.arxiv.orgArXiv Paper Archive