> ## Documentation Index
> Fetch the complete documentation index at: https://docs.galtea.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Outbound connectivity reference

> Every outbound destination the platform can reach, for a firewall or proxy allowlist.

Every outbound destination the platform can generate, on one page, so a firewall or proxy
allowlist can be written from this page alone rather than assembled from prose. The policy
that governs this traffic, deny by default behind a hostname allowlist, is in
[Security assurance](/deployment/security-assurance); how each route is set
up is in [Connectivity implementation](/deployment/connectivity-implementation).

Two reading notes:

* **"Install-time" versus "runtime" is the column that matters for review.** A self-hosted
  install needs the install-time rows only while installing or upgrading; at runtime the only
  Galtea-side traffic is the registry token refresh, and everything else goes to endpoints
  you own or chose. This is checkable: grep the values files of the package you receive for
  outbound hostnames, and the registry endpoint is the only Galtea-side address in them.
* Hostnames written as `<placeholder>` are values specific to your deployment: Galtea issues
  the registry account and the `<tenant>` name, and the provider, product, storage and SMTP
  hosts are yours.

## The tables

### Where each destination is

| Destination                                    | Hostname                                                                                                                       | Port                           | Direction                                                                    |
| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------ | ---------------------------------------------------------------------------- |
| Galtea image and chart registry (AWS ECR)      | `<account>.dkr.ecr.eu-west-1.amazonaws.com`, account issued by Galtea                                                          | 443                            | Cluster to internet                                                          |
| NetBird operator image and chart               | `ghcr.io`                                                                                                                      | 443                            | Cluster to internet                                                          |
| Redis-HA Helm chart                            | `dandydeveloper.github.io`                                                                                                     | 443                            | Cluster or CI to internet                                                    |
| Redis-HA container images                      | `public.ecr.aws` (Redis, Sentinel and HAProxy), `quay.io` (the metrics exporter) and `docker.io` (the init image)              | 443                            | Cluster to internet                                                          |
| VPN control plane, management                  | `vpn.platform.<tenant>.galtea.ai`                                                                                              | TCP 443                        | Your peers (devices, routing VMs, the operator) to internet, outbound only   |
| VPN relay, fallback                            | `rels://relay-vpn.platform.<tenant>.galtea.ai`                                                                                 | TCP 443                        | Your peers to internet, outbound only                                        |
| WireGuard data plane, direct path              | The dedicated VPN load balancer endpoint Galtea exposes for your deployment, a stable public UDP address issued per deployment | UDP 51820                      | Your peers to internet, outbound only                                        |
| LLM provider endpoints                         | Your provider account's endpoint, for example your Azure OpenAI resource; routed solely through the LiteLLM gateway            | 443                            | Cluster (gateway) to provider                                                |
| Your AI product endpoint                       | The hostnames you register for the egress allowlist, or a private address reached through the VPN                              | 443, or your port over the VPN | Cluster (workers) to your endpoint                                           |
| SMTP relay                                     | Your relay's host                                                                                                              | Your relay's port              | Cluster (APIs) to relay                                                      |
| Object storage endpoint                        | Your bucket or account endpoint, for example `https://<your-storage-account>.blob.core.windows.net`                            | 443                            | Cluster to storage, **and your users' browsers to storage**, via signed URLs |
| Slack error webhook, opt-in and off by default | `hooks.slack.com`; the full URL, with its secret path, is issued when you enable the integration                               | 443                            | Cluster to Slack                                                             |

### What each destination carries

| Destination                                    | What it carries                                                                                                                                 | When it fires                                                                                                                  |
| ---------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| Galtea image and chart registry (AWS ECR)      | Container images and Helm charts, as OCI artifacts, pulled with read-only credentials                                                           | Install and upgrade; plus the token-refresh CronJob, which exchanges credentials every 2 hours so pulls keep working           |
| NetBird operator image and chart               | The NetBird Kubernetes operator, pulled from the NetBird project's own registry                                                                 | Install-time, and only if you use the Kubernetes way of joining the VPN                                                        |
| Redis-HA Helm chart                            | The unmodified public Redis-HA chart, from its maintainer rather than from Galtea's registry                                                    | Install and upgrade                                                                                                            |
| Redis-HA container images                      | The images the public Redis-HA chart references, pulled from their upstream registries                                                          | Install, upgrade, and whenever a pod is rescheduled onto a node without the image                                              |
| VPN control plane, management                  | Identity, keys and route policy. Never application traffic                                                                                      | Runtime, continuous, in any deployment using the VPN                                                                           |
| VPN relay, fallback                            | The still-encrypted WireGuard tunnel, when no direct peer-to-peer path exists. The relay cannot decrypt it                                      | Runtime, only when a direct path fails                                                                                         |
| WireGuard data plane, direct path              | Application traffic, encrypted end to end. The tunnel cannot be decrypted in transit                                                            | Runtime, the normal path. If it is blocked, traffic falls back to the relay above, costing latency, never confidentiality      |
| LLM provider endpoints                         | Prompts and completions for evaluations and data generation                                                                                     | Runtime, during evaluation and generation                                                                                      |
| Your AI product endpoint                       | Test traffic against the system under test, with the credentials you supplied                                                                   | Runtime, during test runs                                                                                                      |
| SMTP relay                                     | Transactional email: invitations, notifications                                                                                                 | Runtime                                                                                                                        |
| Object storage endpoint                        | Uploaded files and stored artifacts                                                                                                             | Runtime. The browser path is the one people forget: see [Connectivity implementation](/deployment/connectivity-implementation) |
| Slack error webhook, opt-in and off by default | Error events only: service name, error type and message, correlation identifiers. Never test data, prompts, model outputs or evaluation results | Runtime, only if you enabled it. Removing the URL from your values turns it off                                                |

## What is deliberately absent

* **No telemetry endpoint.** There is no analytics, usage or tracing destination pointing at
  Galtea. Tracing, if you enable it, targets a collector inside your own cluster. See
  [Model 5: Self-hosted](/deployment/model-self-hosted).
* **No license or activation callback.** The deployment needs no online activation and no
  continuous connectivity to Galtea.
* **The database is not in these tables** because it is reached inside your network, not over
  the internet: allow the cluster's node subnet through its firewall per
  [Prerequisites checklist](/deployment/prerequisites-checklist).

Air-gapped installs remove the registry and chart rows by mirroring images and charts into
your internal registry, by agreement: see
[Installation and lifecycle](/deployment/install-and-lifecycle).
