October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

How to Restrict Network Access to GitLab AI Gateway

GitLab AI Gateway egress, Agent Platform execution sandbox policy, and GitLab application connectivity are separate controls. Match each allowlist to your deployment mode and licensing.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restricting network access to GitLab AI Gateway means controlling two different paths: outbound connections made by a self-hosted AI Gateway container, and the network sandbox used by GitLab Duo Agent Platform remote execution. They are separate controls. Before adding firewall rules, identify where the Gateway and model run, which features are enabled, and whether the subscription uses online or offline licensing; there is no single allowlist that fits every deployment.

Choose the control that matches the traffic you need to restrict

A self-hosted Gateway container’s outbound traffic is governed by your infrastructure controls, such as firewall, container-network, or proxy policy. Agent Platform’s remote execution sandbox is a GitLab product policy for agent execution. It controls destinations available to that execution environment; it does not replace firewall rules for the Gateway or GitLab application host.

As an Amazon Associate I earn from qualifying purchases.

  • Gateway egress: Apply infrastructure-level egress rules to the Gateway container.
  • Agent execution: Configure the Agent Platform network sandbox at the instance or top-level group level, and decide whether projects may extend it.
  • GitLab application egress: Separately allow the GitLab instance to reach GitLab services used by applicable Agent Platform features.

If your scope includes more than one of these components, configure and verify each network path independently.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identify your deployment before building an allowlist

GitLab documents fully self-hosted, hybrid, and GitLab-hosted AI Gateway configurations. A fully self-hosted Gateway and model can operate in an isolated network. Using GitLab-managed models for any features makes the deployment hybrid for those features and requires internet connectivity. A GitLab-hosted Gateway configuration also requires internet connectivity. See GitLab’s self-hosted models documentation for deployment distinctions.

#1 Best Overall
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Deployment or feature Where inference runs Connectivity implication
Fully self-hosted Self-hosted Gateway and self-hosted model Can operate in a fully isolated network, subject to the actual services and licensing configuration in use.
Hybrid Some features use self-hosted models; others use GitLab-managed models Internet access is required for features using GitLab-managed models; allow only the connections those features need.
GitLab-hosted AI Gateway GitLab-hosted Gateway Requires internet connectivity; requirements depend on the features and services used.

Licensing also changes the requirements. The Gateway installation guidance identifies customers.gitlab.com for license validation unless you use an offline license. Agent Platform’s online-license service connections include additional GitLab destinations. Do not copy an example provider hostname list as a universal rule: the configured model provider and enabled features determine the endpoints.

Restrict outbound traffic from a self-hosted Gateway container

GitLab’s AI Gateway installation guidance recommends restricting the Gateway container’s outbound network access and blocking other outbound traffic. Implement that as a default-deny egress policy, then add only the exceptions required by your configuration.

  1. Identify the Gateway container’s configured GitLab URL. Permit the GitLab instance URL configured as AIGW_GITLAB_URL.
  2. Identify the model provider in use. Permit the endpoint or endpoints for that configured provider. GitLab does not give one universal provider allowlist in the cited installation guidance; use the endpoints applicable to your provider and features.
  3. Account for licensing. Permit customers.gitlab.com for license validation when applicable. The installation guidance excludes this requirement when an offline license is used.
  4. Block other Gateway-container egress. Avoid broad outbound access that is not needed by the deployment.
  5. Test in a non-production environment. Verify the Gateway and enabled features before applying the policy in production, because an overly restrictive rule can break functionality.

Do not add Hugging Face access to work around tokenizer startup issues

GitLab says the self-hosted Gateway image precaches its tokenizer, so runtime access to huggingface.co should not occur. If startup behavior suggests otherwise, inspect the pod’s mounted cache and configuration rather than widening outbound access to Hugging Face.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
WatchGuard Firebox T45-PoE Network Security/Firewall Appliance (WGT47000-US+WGT470063)
  • WatchGuard Firebox T45 tabletop appliances bring enterprise-level network security to small office/branch office and retail environments. These appliances are small-footprint, cost-effective security powerhouses that deliver all the features present in WatchGuard’s higher-end UTM appliances, including all security capabilities, such as AI-powered anti-malware, threat correlation, and DNS-filtering.
  • 5G and Wi-Fi 6 enabled models available. Up to 3.94 Gbps firewall throughput, 5 x 1Gb ports, 30 Branch Office VPNs
  • Zero-touch deployment makes it possible to eliminate much of the labor involved in setting up a Firebox to connect to your network - all without having to leave your office. A robust, Cloud-based deployment and configuration tool comes standard with WatchGuard Firebox appliances. Local staff connects the device to power and the Internet, and the appliance connects to the Cloud for all its configuration settings.
  • Firebox T45 models make network optimization easy. With integrated SD-WAN and optional 5G technology, you can ensure failover to the cellular network, minimize disruptive connectivity, and establish secure and reliable connections for small offices.
  • Standard Support includes 24x7 access to technical support, with an unlimited number of incidents with a targeted response time of 24 hours for low priority, 8 hours for medium priority, 4 hours for high priority, and live calls for critical priority. Support is Web-Based and Phone-Based.

Configure the Agent Platform remote execution sandbox

For Agent Platform execution, GitLab documents network access controls introduced in GitLab 18.11. Confirm that the deployed release and feature state support the controls before relying on them. On Self-Managed, use Admin > GitLab Duo > Change configuration and locate the GitLab Duo network access section. On GitLab.com, the corresponding controls are available for a top-level group.

Administrators can configure recommended domains, allowed domains, blocked domains, whether Unix sockets are permitted, and whether projects can extend the network sandbox. These settings are inherited by projects. The policy mode determines how project configuration interacts with administrator policy:

Policy behavior Flexible mode Strict mode
Project allowed_domains Merged with the administrator’s allowed domains. Ignored; projects cannot add allowed domains through this setting.
Project denied_domains Merged with the administrator’s blocked domains. Can tighten the policy with additional deny rules.
Recommended domains and Unix sockets Project values can override the administrator setting. A project can disable these when enabled by the administrator, but cannot enable them if the administrator disabled them.

Use flexible mode only when project-level extension is intended. Use strict mode when projects must not add destinations to the administrator’s allowlist. For the documented controls and policy interaction, see Remote execution environment sandbox.

Rank #3
Sale
Ubiquiti Unifi Security Appliance (USG), Single,White
  • Integration with Unifi Controller. Powerful firewall performance
  • Convenient VLAN support. QoS for enterprise VoIP
  • VPN server for secure communications. 10/100/1000Base-T
  • 3 Ports - Management Port - SlotsGigabit Ethernet - Wall Mountable, Desktop
  • Refer instruction manual for troubleshooting steps.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Allow the GitLab application and runner paths separately

The Gateway is not the only component that may need network access. For applicable Agent Platform features, the GitLab application instance connects to the Workflow service. Runners do not connect directly to that service; they connect to GitLab. Depending on runner configuration, runners may also need GitLab destinations for the Duo CLI package and default container image.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Connection initiator Destination Purpose and when needed Port or protocol
GitLab application instance duo-workflow-svc.runway.gitlab.net Workflow service connection for applicable Agent Platform features. Port 443; HTTPS/HTTP/2.
GitLab application instance customers.gitlab.com License or subscription synchronization in GitLab’s online-license Agent Platform requirements. Port 443.
GitLab application instance cloud.gitlab.com Quota checks in GitLab’s online-license Agent Platform requirements. Port 443.
Runner GitLab instance Runner-to-GitLab communication; runners do not connect directly to the Workflow service. Not stated in the cited Agent Platform requirements; follow your GitLab instance’s configured connection.
Runner gitlab.com Duo CLI package, depending on runner configuration. Port 443.
Runner registry.gitlab.com Default container image, depending on runner configuration. Port 443.

These requirements are described in GitLab’s self-hosted models and GitLab Duo configuration documentation. The online-license table does not make those destinations universal requirements for every deployment; check which Agent Platform features and licensing arrangement you use.

Account for DNS and proxy behavior

If the GitLab host sends requests through an HTTP or HTTPS proxy, it must still be able to resolve public DNS names. A proxy route does not remove that name-resolution requirement. Also check proxy and firewall request-duration or idle timeouts: they must accommodate long-lived streaming responses. GitLab covers these considerations in its GitLab Duo configuration guidance.

Verify the rules with the relevant health checks and logs

  1. Run GitLab’s Duo health check after applying the relevant network rules. Use the health-check guidance in Configure GitLab Duo.
  2. For self-hosted models, review the model-serving platform’s access logs to confirm whether requests arrive and whether responses are returned. GitLab’s self-hosted model configuration guidance describes configuring Duo features to use self-hosted models.
  3. When a network test fails, inspect firewall and proxy access. Use the failed connection and logs to identify the blocked path; do not open unrelated destinations speculatively.

Use the offline deployment path only when its prerequisites fit

If the environment cannot reach the public internet, GitLab documents an offline deployment path for GitLab Duo Agent Platform Self-Hosted. It requires internal transfer of the Gateway and executor images, model weights, and inference-server image. GitLab also says an opt-out exemption from cloud licensing must be arranged before purchase. Confirm licensing eligibility and follow the offline deployment documentation before planning a fully disconnected installation.

Quick Recap

SaleBestseller No. 3
Ubiquiti Unifi Security Appliance (USG), Single,White
Ubiquiti Unifi Security Appliance (USG), Single,White
Integration with Unifi Controller. Powerful firewall performance; Convenient VLAN support. QoS for enterprise VoIP
$164.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.