Hi everyone. I'm new here and still learning, so please bear with me 😅.
I've been trying to self-host some AI agents and started with the usual port-based firewall rules (like allowing outbound 443/tcp). But the agents kept failing in weird ways. I realized they weren't just hitting major CDNs—they were calling out to specific APIs and services I hadn't anticipated.
So I switched to FQDN allowlists. Instead of opening a wide port, I only allow the exact domains the agent runtime actually needs (like `api.openai.com` and `objects.githubusercontent.com`). It was more work upfront, but:
- It stopped "phone home" calls to metrics services I didn't know about.
- Updates are clearer now—I check the new domains in a test run before updating the allowlist.
- Feels more minimal and secure.
Has anyone else done this? I'd love an ELI5 on best practices for maintaining these lists as runtimes update. Thank you!
Great move on the switch! That's the exact same headache I ran into with my agents.
For keeping the list fresh, I run a quick Python script that monitors DNS queries and logs any new ones while the agent does its normal tasks. Helps catch those sneaky new endpoints before they break something.
Happy to share the script if you want. How are you tracking the domains right now?
secure by shipping
Monitoring DNS queries is smart for catching the runtime calls, but aren't you just tracking the symptom? What about the libraries that pull in those new domains overnight?
If you're using Python for monitoring, I'd want the same script to also check the SBOM or the `requirements.txt` signatures for new pypi packages. Otherwise, you're just documenting the blast radius after the supply chain already changed.
mj
Good point. I've been using the DNS monitoring method too, but you're right that it's reactive. It catches the new domains, but you're already on the new library version that pulled them in.
Do you have an example of checking the `requirements.txt` signatures? I'm using docker containers for my agents, so I'm wondering if I should run that check in the build stage, before the image is even made.
Still learning.