Logo

Command Palette

Search for a command to run...

Using Cloud 66 via a firewall

Overview

Most modern web infrastructure has built-in security systems, including firewalls, that are enabled by default. These can interfere with Cloud 66's systems and prevent us from reaching your servers to deploy and manage your applications. In order for Cloud 66's services to function correctly, we need you to ensure that your security systems give us the access we need.

Ports that Cloud 66 requires

In order to manage your servers we need full access to two TCP ports from specific (static) IP addresses:

If your cluster is behind a deployment gateway, open only port 22 on your gateway server instead. Cloud 66 reaches both SSH and the Kubernetes API on your cluster servers through it, and opens ports 22 and 6443 on them to your gateway's private IP address.

In general, with most cloud providers, we are able to gain access to these ports and set everything up automatically. It's generally only when we're dealing with registered servers, or with cloud accounts in which additional security has been implemented, that we need your manual intervention.

Cloud 66's authorized IP addresses

Cloud 66 connects to users' servers from a set of authorized IP addresses:

All provisioned servers are configured to only allow SSH (and other secure) connections from these addresses. We may add new IP addresses to this range from time to time. You can check the very latest list of IP addresses via this link.