Skip to main content
Conduit needs no inbound access beyond the port it listens on. This page is the outbound picture — what to allow if egress from the Conduit container is filtered, and what each host is actually used for. A Conduit instance with no connectors, no email provider, and no IAM database authentication configured makes no outbound requests at all. There is no phone-home, license check, or update poll. (What the image build downloads is separate and also enumerated — see Build from Source.)

Fixed hosts

These are the only hostnames compiled into Conduit. Each is contacted only when the feature next to it is in use, so an instance that doesn’t use the feature never resolves the host.

Hosts you configure

There is no fixed list for these — they are whatever an administrator enters, and each is contacted only by the feature that owns it:
  • Identity providers — issuer discovery, token, and JWKS endpoints for each identity provider you add, contacted during sign-in.
  • Upstream MCP servers — every connector of type URL or SSE, contacted on tools/list and tools/call. Conduit’s built-in catalog offers mcp.linear.app, mcp.supabase.com, and mcp.atlassian.com as one-click suggestions; they are contacted only once an administrator actually adds one.
  • OpenAPI and GraphQL connectors — the API base URL you configure, plus the spec or schema URL if you point at one rather than pasting it.
  • SMTP server — your mail host, when the email provider is SMTP. This is a direct SMTP connection, not HTTP, and is not subject to the hardening below.
  • Instance telemetry exporters — the OTLP collectors instance administrators configure in Settings → Instance → Telemetry, or via the standard OTEL_EXPORTER_OTLP_* variables. Deliberately exempt from the hardening below, because a collector normally is on a private in-cluster address.
  • Workspace telemetry exporters — the https OTLP endpoints workspace administrators configure in their workspace’s Settings → Telemetry. These are tenant-supplied, so they are not exempt: they go through the hardened client like connectors, and a hostname that resolves to a private address is refused unless listed in CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS. See Telemetry Export.
  • OAuth client metadata documents — an https URL supplied by a connecting MCP client, fetched when it asks to authorize so Conduit can identify it. The host is the client vendor’s own, so it is not a fixed host; which clients may then connect is decided per workspace under Settings → MCP Clients (see Governing connected clients).

Hosts the browser reaches

These are loaded by the browser of someone using the web UI, not by the Conduit container, so they belong in a user-network policy rather than a container egress rule:
  • pipedream.com — the connect-account flow runs in an iframe from this origin.
  • Connector icons — www.google.com/s2/favicons and assets.pipedream.net for catalog entries, plus any https URL an administrator sets as a connector’s icon. The Content-Security-Policy allows images from any https origin for this reason; every other directive is pinned.
  • pipedream.com/docs/conduit — only if /docs/ is configured to redirect to the public documentation site instead of serving the copy embedded in the image. The embedded copy loads nothing from outside the instance.

How outbound requests are hardened

Every HTTP request Conduit makes — to a fixed host above or one you configured — goes through a single hardened client. It refuses to connect to private, loopback, link-local, and other special-use addresses, checked after DNS resolution so a hostname that resolves to an internal address is caught too. For a well-known NAT64 (64:ff9b::/96) or 6to4 (2002::/16) address, Conduit checks the IPv4 address it carries. Local-use NAT64, IPv4-compatible, IPv4-translated and Teredo addresses are blocked whatever IPv4 address they carry. It never follows redirects, and it requires https. Response sizes are capped, and a reply over the cap is refused rather than truncated. Two settings adjust this, and both are exceptions rather than modes:
  • CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS lists exact hostnames that may resolve to a private address — see Private endpoints and gateways below for the rules and worked examples. https is still required.
  • CONDUIT_SAFEHTTP_ALLOW_LOCALHOST is for development only: it permits plain http to loopback, so a local identity provider or upstream on http://localhost:PORT is reachable. Never enable it in production.
Three exemptions bypass this client: the SMTP connection, the OTLP collector (both noted above), and the AWS credential lookups made when CONDUIT_DATABASE_AUTH=rds-iam is set — those go through the AWS SDK, whose endpoints are fixed AWS infrastructure rather than configurable URLs. The database connection itself is PostgreSQL wire protocol, not HTTP, like the SMTP case.

Private endpoints and gateways

Sometimes a host you trust resolves to a private address on purpose: a vendor’s API consumed through a private endpoint or gateway (e.g. AWS PrivateLink), a service behind an enterprise egress proxy, or an MCP server on your own network — including one deployed into an isolated VPC or private subnet that only Conduit can reach. The hardened client cannot tell that from an SSRF attempt, so the request is refused with an error like:
CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS lifts the block for hosts you name: a comma-separated list of exact hostnames that are allowed to resolve to private addresses.
  • Hostnames only. No URLs, ports, IP addresses, CIDR ranges, or wildcards — an invalid entry refuses to boot rather than silently weakening the protection. Matching is exact, so list every hostname; subdomains are not covered.
  • https is still required, and the certificate must be valid for the hostname. A private endpoint that preserves the service’s public DNS name (as PrivateLink does) satisfies this as-is.
  • Read at boot. Set it in the container’s environment and restart — re-saving the connector is not enough.

Example: Pipedream through a private endpoint

The Pipedream connector reaches two hosts (see Fixed hosts): api.pipedream.com and remote.mcp.pipedream.net. If they resolve to private addresses in your network, allow both:
If a workspace overrides the Pipedream MCP server URL, list that URL’s hostname in place of remote.mcp.pipedream.net.

Example: an MCP server on your own network

List the hostname from the connector’s URL — for a connector pointing at https://mcp.internal.example.com/mcp:
On Kubernetes the variable goes through the Helm chart’s extraEnv (see Kubernetes):
The same recipe covers every other host you configure that lives on a private network — an on-premises identity provider, an internal OpenAPI or GraphQL endpoint.