Forum

Notifications
Clear all

Switched from port-based to FQDN allowlists, here is why

4 Posts
4 Users
0 Reactions
17 Views
(@newb_jen_sec)
Eminent Member
Joined: 3 months ago
Posts: 24
Topic starter   [#1658]

Hi everyone. I'm new here and still learning, so please bear with me 😅.

I've been trying to self-host some AI agents and started with the usual port-based firewall rules (like allowing outbound 443/tcp). But the agents kept failing in weird ways. I realized they weren't just hitting major CDNs—they were calling out to specific APIs and services I hadn't anticipated.

So I switched to FQDN allowlists. Instead of opening a wide port, I only allow the exact domains the agent runtime actually needs (like `api.openai.com` and `objects.githubusercontent.com`). It was more work upfront, but:

- It stopped "phone home" calls to metrics services I didn't know about.
- Updates are clearer now—I check the new domains in a test run before updating the allowlist.
- Feels more minimal and secure.

Has anyone else done this? I'd love an ELI5 on best practices for maintaining these lists as runtimes update. Thank you!



   
Quote
(@advocate_tools)
Eminent Member
Joined: 3 months ago
Posts: 22
 

Great move on the switch! That's the exact same headache I ran into with my agents.

For keeping the list fresh, I run a quick Python script that monitors DNS queries and logs any new ones while the agent does its normal tasks. Helps catch those sneaky new endpoints before they break something.

Happy to share the script if you want. How are you tracking the domains right now?


secure by shipping


   
ReplyQuote
(@supply_chain_auditor)
Eminent Member
Joined: 3 months ago
Posts: 20
 

Monitoring DNS queries is smart for catching the runtime calls, but aren't you just tracking the symptom? What about the libraries that pull in those new domains overnight?

If you're using Python for monitoring, I'd want the same script to also check the SBOM or the `requirements.txt` signatures for new pypi packages. Otherwise, you're just documenting the blast radius after the supply chain already changed.


mj


   
ReplyQuote
(@practical_threat_bob)
Eminent Member
Joined: 3 months ago
Posts: 30
 

Good point. I've been using the DNS monitoring method too, but you're right that it's reactive. It catches the new domains, but you're already on the new library version that pulled them in.

Do you have an example of checking the `requirements.txt` signatures? I'm using docker containers for my agents, so I'm wondering if I should run that check in the build stage, before the image is even made.


Still learning.


   
ReplyQuote