| Galtea image and chart registry (AWS ECR) | Container images and Helm charts, as OCI artifacts, pulled with read-only credentials | Install and upgrade; plus the token-refresh CronJob, which exchanges credentials every 2 hours so pulls keep working |
| NetBird operator image and chart | The NetBird Kubernetes operator, pulled from the NetBird project’s own registry | Install-time, and only if you use the Kubernetes way of joining the VPN |
| Redis-HA Helm chart | The unmodified public Redis-HA chart, from its maintainer rather than from Galtea’s registry | Install and upgrade |
| Redis-HA container images | The images the public Redis-HA chart references, pulled from their upstream registries | Install, upgrade, and whenever a pod is rescheduled onto a node without the image |
| VPN control plane, management | Identity, keys and route policy. Never application traffic | Runtime, continuous, in any deployment using the VPN |
| VPN relay, fallback | The still-encrypted WireGuard tunnel, when no direct peer-to-peer path exists. The relay cannot decrypt it | Runtime, only when a direct path fails |
| WireGuard data plane, direct path | Application traffic, encrypted end to end. The tunnel cannot be decrypted in transit | Runtime, the normal path. If it is blocked, traffic falls back to the relay above, costing latency, never confidentiality |
| LLM provider endpoints | Prompts and completions for evaluations and data generation | Runtime, during evaluation and generation |
| Your AI product endpoint | Test traffic against the system under test, with the credentials you supplied | Runtime, during test runs |
| SMTP relay | Transactional email: invitations, notifications | Runtime |
| Object storage endpoint | Uploaded files and stored artifacts | Runtime. The browser path is the one people forget: see Connectivity implementation |
| Slack error webhook, opt-in and off by default | Error events only: service name, error type and message, correlation identifiers. Never test data, prompts, model outputs or evaluation results | Runtime, only if you enabled it. Removing the URL from your values turns it off |