This section lists the endpoints required for the Data Integrity Suite agent's basic operation and for integrating Google BigQuery as a replication target. If your environment restricts outbound web traffic, ensure outbound HTTPS access to these domain names is explicitly allowed. The agent does not accept inbound connections and does not require any inbound traffic or open ports.
Required domain names for all regions
These endpoints must be allowed for the Data Integrity Suite agent to function correctly across all regions. These are necessary for agent installation, authentication, container interactions, and cloud integrations:
| Domain name | Description |
|---|---|
repo1.maven.org |
Required to download Java libraries and tools when building projects using Maven. |
|
|
Required for pulling docker images during agent installation from AWS ECR (Elastic Container Registry). |
api.ecr.us-east-1.amazonaws.com |
Necessary for interacting with AWS ECR for container-related activities, such as pulling images. |
api.github.com |
Used for accessing GitHub repositories for code updates or dependencies. |
auth.docker.io |
Required for authentication when pulling docker images from docker hub. |
awscli.amazonaws.com |
Required for AWS CLI operations, such as configuring and managing AWS services used by the Data Integrity Suite. |
cdn.cloud.precisely.com |
Serves content and updates required for Data Integrity Suite operations from Precisely’s cloud. |
collect.traefik.io |
Used for collecting monitoring and operational metrics related to the Data Integrity Suite agent’s health. |
precisely-agent-operator-installation-bucket.s3.amazonaws.com |
Needed for accessing the Precisely agent operator installation resources on AWS S3. |
prod-us-east-1-starport-layer-bucket.s3.us-east-1.amazonaws.com |
Used for accessing specific data or resources related to agent operation on AWS S3. |
production.cloudflare.docker.com |
Required for docker related activities hosted via cloudflare, ensuring proper agent operation and security. |
registry-1.docker.io |
Required for pulling docker images from docker hub. |
rpm.rancher.io |
Needed for accessing RPM packages for agent installation and updates on supported Linux distributions. |
sts.us-east-1.amazonaws.com |
Required for AWS STS (Security Token Service) for identity and access management related to agent operations. |
update.traefik.io |
Used for retrieving updates and configurations for Traefik, a reverse proxy used by the Data Integrity Suite agent. |
Required domain names for US1 region
In addition to the general endpoints, the following endpoints are needed specifically for the US1 region:
| Domain name | Description |
|---|---|
agent-management.dis-platform.cloud.precisely.com |
Used for managing agent configurations, updates, and communication with the DI platform for the US1 region. |
agent-sqs-request-response-bucket-prd.s3.amazonaws.com |
Required for sending and receiving data via AWS SQS for agent operations in the US1 region. |
docker-images-prod.s3.dualstack.us-east-1.amazonaws.com |
Required for accessing docker images stored on AWS S3 for agent installation and updates in the US1 region. |
sqs.us-east-1.amazonaws.com |
Used for AWS SQS messaging services to facilitate communication between agent components in the US1 region. |
precisely-agent-operator-installation-bucket.s3.us-east-1.amazonaws.com |
Required for downloading agent operator installation artefacts from AWS S3 for agent setup in the US1 region. |
s3-r-w.us-east-1.amazonaws.com |
Required for read and write operations to AWS S3 used by the agent during installation and runtime in the US1 region. |
ch5lej6nw7420.credentials.iot.us-east-1.amazonaws.com |
Required for obtaining temporary security credentials via AWS IoT for agent authentication in the US1 region. |
Required domain names for EU1 region
In addition to the general endpoints, the following endpoints are needed specifically for the EU1 region:
| Domain name | Description |
|---|---|
agent-management.dis-platform.eu1.cloud.precisely.com |
Used for managing agent configurations, updates, and communication with the DI platform for the EU region. |
agent-sqs-request-response-bucket-prd-eu-west-1.s3.eu-west-1.amazonaws.com |
Required for sending and receiving data via AWS SQS for agent operations in the EU region. |
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.com |
Required for accessing docker images stored on AWS S3 for agent installation and updates in the EU region. |
sqs.eu-west-1.amazonaws.com |
Used for AWS SQS messaging services to facilitate communication between agent components in the EU region. |
|
|
Required for AWS STS (Security Token Service) for identity and access management related to agent operations in EU1 region. |
precisely-agent-operator-installation-bucket.s3.eu-west-1.amazonaws.com |
Required for downloading agent operator installation artefacts from AWS S3 for agent setup in the EU1 region. |
s3-r-w.eu-west-1.amazonaws.com |
Required for read and write operations to AWS S3 used by the agent during installation and runtime in the EU1 region. |
ch5lej6nw7420.credentials.iot.eu-west-1.amazonaws.com |
Required for obtaining temporary security credentials via AWS IoT for agent authentication in the EU1 region. |
Required domain names for EU2 region
In addition to the general endpoints, the following endpoints are needed specifically for the EU2 region:
| Domain name | Description |
|---|---|
agent-sqs-request-response-bucket-prd-eu-west-2.s3.eu-west-2.amazonaws.com |
Required for storing request and response payloads used by AWS SQS for agent operations in the EU2 region. |
docker-images-prod.s3.dualstack.us-east-1.amazonaws.com |
Required for downloading Docker images used by the agent from AWS S3 during installation and upgrades. |
precisely-agent-operator-installation-bucket.s3.eu-west-2.amazonaws.com
|
Required for downloading agent operator installation artefacts from AWS S3 for agent setup in the EU2 region. |
s3-r-w.eu-west-2.amazonaws.com |
Required for read and write operations to AWS S3 used by the agent during installation and runtime in the EU2 region. |
|
|
Required for sending and receiving data via AWS SQS for agent operations in the EU2 region. |
sts.eu-west-2.amazonaws.com |
Required for obtaining temporary AWS security tokens used by the agent for authentication and access control in the EU2 region. |
ch5lej6nw7420.credentials.iot.eu-west-2.amazonaws.com |
Required for obtaining temporary security credentials via AWS IoT for agent authentication in the EU2 region. |
Required domain names for GB1 region
In addition to the general endpoints, the following endpoints are needed specifically for the GB1 region:
| Domain name | Description |
|---|---|
agent-management.dis-platform.gb1.cloud.precisely.com |
Required for managing agent configuration, lifecycle, and communication with the Data Integrity Suite platform in the GB1 region. |
agent-sqs-request-response-bucket-prd-eu-west-2.s3.eu-west-2.amazonaws.com |
S3 bucket used for exchanging request and response data between the agent and cloud services (job payloads, results) |
docker-images-prod.s3.dualstack.us-east-1.amazonaws.com |
Central S3 endpoint used to download container images and installation dependencies required by the agent |
precisely-agent-operator-installation-bucket.s3.eu-west-2.amazonaws.com |
S3 bucket containing agent installation packages and operator components |
s3-r-w.eu-west-2.amazonaws.com |
General AWS S3 endpoint used by the agent for read/write operations to storage |
sqs.eu-west-2.amazonaws.com |
AWS Simple Queue Service (SQS) endpoint used for messaging between the agent and the platform |
sts.eu-west-2.amazonaws.com |
AWS Security Token Service (STS) endpoint used for secure authentication and temporary credential generation |
ch5lej6nw7420.credentials.iot.eu-west-2.amazonaws.com |
AWS IoT credentials provider endpoint used for agent authentication and token retrieval |
Required domain names for AU1 region
In addition to the general endpoints, the following endpoints are needed specifically for the AU1 region:
| Domain name | Description |
|---|---|
agent-management.dis-platform.au1.cloud.precisely.com |
Required for managing agent configuration, lifecycle, and communication with the Data Integrity Suite platform in the AU1 region. |
agent-sqs-request-response-bucket-prd-ap-southeast-2.s3.ap-southeast-2.amazonaws.com |
Required for storing request and response payloads used by AWS SQS for agent operations in the AU1 region. |
docker-images-prod.s3.dualstack.us-east-1.amazonaws.com |
Required for downloading Docker images used by the agent from AWS S3 during installation and upgrades. |
precisely-agent-operator-installation-bucket.s3.ap-southeast-2.amazonaws.com |
Required for downloading agent operator installation artefacts from AWS S3 for agent setup in the AU1 region. |
|
|
Required for read and write operations to AWS S3 used by the agent during installation and runtime in the AU1 region. |
sqs.ap-southeast-2.amazonaws.com |
Required for sending and receiving data via AWS SQS for agent operations in the AU1 region. |
sts.ap-southeast-2.amazonaws.com |
Required for obtaining temporary AWS security tokens used by the agent for authentication and access control in the AU1 region. |
ch5lej6nw7420.credentials.iot.ap-southeast-2.amazonaws.com |
Required for obtaining temporary security credentials via AWS IoT for agent authentication in the AU1 region. |
Domain names for BigQuery as replication target
If using Google BigQuery as a replication target, the following endpoint should also be allowed:
| Domain name | Description |
|---|---|
bigquery.googleapis.com |
Required for integrating with BigQuery for data replication tasks, including querying and transferring data. |
metadata.google.internal |
Used for accessing internal metadata within google cloud environments for BigQuery integration. |
oauth2.googleapis.com |
Necessary for OAuth2 authentication to securely connect to google BigQuery and other google cloud services. |
storage.googleapis.com |
Required for accessing google cloud storage to store or retrieve data for BigQuery replication. |