Fixed hosts
These are the only hostnames compiled into Conduit. Each is contacted only when the feature next to it is in use, so an instance that doesn’t use the feature never resolves the host.Hosts you configure
There is no fixed list for these — they are whatever an administrator enters, and each is contacted only by the feature that owns it:- Identity providers — issuer discovery, token, and JWKS endpoints for each identity provider you add, contacted during sign-in.
- Upstream MCP servers — every connector of type URL or SSE, contacted on
tools/listandtools/call. Conduit’s built-in catalog offersmcp.linear.app,mcp.supabase.com, andmcp.atlassian.comas one-click suggestions; they are contacted only once an administrator actually adds one. - OpenAPI and GraphQL connectors — the API base URL you configure, plus the spec or schema URL if you point at one rather than pasting it.
- SMTP server — your mail host, when the email provider is SMTP. This is a direct SMTP connection, not HTTP, and is not subject to the hardening below.
- Instance telemetry exporters — the OTLP collectors instance
administrators configure in Settings → Instance → Telemetry, or via the
standard
OTEL_EXPORTER_OTLP_*variables. Deliberately exempt from the hardening below, because a collector normally is on a private in-cluster address. - Workspace telemetry exporters — the
httpsOTLP endpoints workspace administrators configure in their workspace’s Settings → Telemetry. These are tenant-supplied, so they are not exempt: they go through the hardened client like connectors, and a hostname that resolves to a private address is refused unless listed inCONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS. See Telemetry Export. - OAuth client metadata documents — an
httpsURL supplied by a connecting MCP client, fetched when it asks to authorize so Conduit can identify it. The host is the client vendor’s own, so it is not a fixed host; which clients may then connect is decided per workspace under Settings → MCP Clients (see Governing connected clients).
Hosts the browser reaches
These are loaded by the browser of someone using the web UI, not by the Conduit container, so they belong in a user-network policy rather than a container egress rule:pipedream.com— the connect-account flow runs in an iframe from this origin.- Connector icons —
www.google.com/s2/faviconsandassets.pipedream.netfor catalog entries, plus anyhttpsURL an administrator sets as a connector’s icon. The Content-Security-Policy allows images from anyhttpsorigin for this reason; every other directive is pinned. pipedream.com/docs/conduit— only if/docs/is configured to redirect to the public documentation site instead of serving the copy embedded in the image. The embedded copy loads nothing from outside the instance.
How outbound requests are hardened
Every HTTP request Conduit makes — to a fixed host above or one you configured — goes through a single hardened client. It refuses to connect to private, loopback, link-local, and other special-use addresses, checked after DNS resolution so a hostname that resolves to an internal address is caught too. For a well-known NAT64 (64:ff9b::/96) or 6to4 (2002::/16) address, Conduit
checks the IPv4 address it carries. Local-use NAT64, IPv4-compatible,
IPv4-translated and Teredo addresses are blocked whatever IPv4 address they
carry.
It never follows redirects, and it requires https. Response sizes are capped,
and a reply over the cap is refused rather than truncated.
Two settings adjust this, and both are exceptions rather than modes:
CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTSlists exact hostnames that may resolve to a private address — see Private endpoints and gateways below for the rules and worked examples.httpsis still required.CONDUIT_SAFEHTTP_ALLOW_LOCALHOSTis for development only: it permits plainhttpto loopback, so a local identity provider or upstream onhttp://localhost:PORTis reachable. Never enable it in production.
CONDUIT_DATABASE_AUTH=rds-iam is set — those go through the AWS SDK, whose
endpoints are fixed AWS infrastructure rather than configurable URLs. The
database connection itself is PostgreSQL wire protocol, not HTTP, like the
SMTP case.
Private endpoints and gateways
Sometimes a host you trust resolves to a private address on purpose: a vendor’s API consumed through a private endpoint or gateway (e.g. AWS PrivateLink), a service behind an enterprise egress proxy, or an MCP server on your own network — including one deployed into an isolated VPC or private subnet that only Conduit can reach. The hardened client cannot tell that from an SSRF attempt, so the request is refused with an error like:CONDUIT_SAFEHTTP_ALLOWED_PRIVATE_HOSTS lifts the block for hosts you name: a
comma-separated list of exact hostnames that are allowed to resolve to private
addresses.
- Hostnames only. No URLs, ports, IP addresses, CIDR ranges, or wildcards — an invalid entry refuses to boot rather than silently weakening the protection. Matching is exact, so list every hostname; subdomains are not covered.
httpsis still required, and the certificate must be valid for the hostname. A private endpoint that preserves the service’s public DNS name (as PrivateLink does) satisfies this as-is.- Read at boot. Set it in the container’s environment and restart — re-saving the connector is not enough.
Example: Pipedream through a private endpoint
The Pipedream connector reaches two hosts (see Fixed hosts):api.pipedream.com and remote.mcp.pipedream.net. If they resolve to private
addresses in your network, allow both:
remote.mcp.pipedream.net.
Example: an MCP server on your own network
List the hostname from the connector’s URL — for a connector pointing athttps://mcp.internal.example.com/mcp:
extraEnv (see
Kubernetes):