|
1 | 1 | ---
|
2 | 2 | ms.service: azure-arc
|
3 | 3 | ms.topic: include
|
4 |
| -ms.date: 09/28/2023 |
| 4 | +ms.date: 02/15/2024 |
5 | 5 | ---
|
6 | 6 |
|
7 | 7 | ### [Azure Cloud](#tab/azure-cloud)
|
8 | 8 |
|
9 |
| -> [!IMPORTANT] |
10 |
| -> Azure Arc agents require the following outbound URLs on `https://:443` to function. |
11 |
| -> For `*.servicebus.windows.net`, websockets need to be enabled for outbound access on firewall and proxy. |
12 |
| -
|
13 |
| -| Endpoint (DNS) | Description | |
14 |
| -| ----------------- | ------------- | |
15 |
| -| `https://management.azure.com` | Required for the agent to connect to Azure and register the cluster. | |
16 |
| -| `https://<region>.dp.kubernetesconfiguration.azure.com` | Data plane endpoint for the agent to push status and fetch configuration information. | |
17 |
| -| `https://login.microsoftonline.com`<br/>`https://<region>.login.microsoft.com`<br/>`login.windows.net`| Required to fetch and update Azure Resource Manager tokens. | |
18 |
| -| `https://mcr.microsoft.com`<br/>`https://*.data.mcr.microsoft.com` | Required to pull container images for Azure Arc agents. | |
19 |
| -| `https://gbl.his.arc.azure.com` | Required to get the regional endpoint for pulling system-assigned Managed Identity certificates. | |
20 |
| -| `https://*.his.arc.azure.com` | Required to pull system-assigned Managed Identity certificates. | |
21 |
| -|`https://k8connecthelm.azureedge.net` | `az connectedk8s connect` uses Helm 3 to deploy Azure Arc agents on the Kubernetes cluster. This endpoint is needed for Helm client download to facilitate deployment of the agent helm chart. | |
22 |
| -|`guestnotificationservice.azure.com`<br/>`*.guestnotificationservice.azure.com`<br/>`sts.windows.net`<br/>`https://k8sconnectcsp.azureedge.net` | For [Cluster Connect](../cluster-connect.md) and for [Custom Location](../custom-locations.md) based scenarios. | |
23 |
| -|`*.servicebus.windows.net` | For [Cluster Connect](../cluster-connect.md) and for [Custom Location](../custom-locations.md) based scenarios. | |
24 |
| -|`https://graph.microsoft.com/` | Required when [Azure RBAC](../azure-rbac.md) is configured. | |
25 |
| -| `*.arc.azure.net`| Required to manage connected clusters in Azure portal. | |
26 |
| -|`https://<region>.obo.arc.azure.com:8084/` | Required when [Cluster Connect](../cluster-connect.md) is configured. | |
27 |
| -|`dl.k8s.io`| Required when [automatic agent upgrade](../agent-upgrade.md#toggle-automatic-upgrade-on-or-off-when-connecting-a-cluster-to-azure-arc) is enabled. | |
28 |
| - |
29 |
| -To translate the `*.servicebus.windows.net` wildcard into specific endpoints, use the command: |
30 |
| - |
31 |
| -```rest |
32 |
| -GET https://guestnotificationservice.azure.com/urls/allowlist?api-version=2020-01-01&location=<region> |
33 |
| -``` |
34 |
| - |
35 |
| -[!INCLUDE [arc-region-note](../../includes/arc-region-note.md)] |
| 9 | +[!INCLUDE [network-requirements-azure-cloud.md](network-requirements-azure-cloud.md)] |
36 | 10 |
|
37 | 11 | ### [Azure Government](#tab/azure-government)
|
38 | 12 |
|
39 |
| -> [!IMPORTANT] |
40 |
| -> Azure Arc agents require the following outbound URLs on `https://:443` to function. |
41 |
| -> For `*.servicebus.usgovcloudapi.net`, websockets need to be enabled for outbound access on firewall and proxy. |
42 |
| -
|
43 |
| -| Endpoint (DNS) | Description | |
44 |
| -| ----------------- | ------------- | |
45 |
| -|`https://management.usgovcloudapi.net` | Required for the agent to connect to Azure and register the cluster. | |
46 |
| -| `https://<region>.dp.kubernetesconfiguration.azure.us` | Data plane endpoint for the agent to push status and fetch configuration information. | |
47 |
| -| `https://login.microsoftonline.us`<br/>`<region>.login.microsoftonline.us` | Required to fetch and update Azure Resource Manager tokens. | |
48 |
| -| `https://mcr.microsoft.com`<br/>`https://*.data.mcr.microsoft.com` | Required to pull container images for Azure Arc agents. | |
49 |
| -| `https://gbl.his.arc.azure.us` | Required to get the regional endpoint for pulling system-assigned Managed Identity certificates. | |
50 |
| -| `https://usgv.his.arc.azure.us` | Required to pull system-assigned Managed Identity certificates. | |
51 |
| -|`https://k8connecthelm.azureedge.net` | `az connectedk8s connect` uses Helm 3 to deploy Azure Arc agents on the Kubernetes cluster. This endpoint is needed for Helm client download to facilitate deployment of the agent helm chart. | |
52 |
| -|`guestnotificationservice.azure.us`<br/>`*.guestnotificationservice.azure.us`<br/>`sts.windows.net`<br/>`https://k8sconnectcsp.azureedge.net` | For [Cluster Connect](../cluster-connect.md) and for [Custom Location](../custom-locations.md) based scenarios. | |
53 |
| -|`*.servicebus.usgovcloudapi.net` | For [Cluster Connect](../cluster-connect.md) and for [Custom Location](../custom-locations.md) based scenarios. | |
54 |
| -|`https://graph.microsoft.com/` | Required when [Azure RBAC](../azure-rbac.md) is configured. | |
55 |
| -|`https://usgovvirginia.obo.arc.azure.us:8084/` | Required when [Cluster Connect](../cluster-connect.md) is configured. | |
56 |
| -|`dl.k8s.io`| Required when [automatic agent upgrade](../agent-upgrade.md#toggle-automatic-upgrade-on-or-off-when-connecting-a-cluster-to-azure-arc) is enabled. | |
57 |
| - |
58 |
| -To translate the `*.servicebus.usgovcloudapi.net` wildcard into specific endpoints, use the command: |
59 |
| - |
60 |
| -```rest |
61 |
| -GET https://guestnotificationservice.azure.us/urls/allowlist?api-version=2020-01-01&location=region |
62 |
| -``` |
63 |
| - |
64 |
| -[!INCLUDE [arc-region-note](../../includes/arc-region-note.md)] |
| 13 | +[!INCLUDE [network-requirements-azure-government.md](network-requirements-azure-government.md)] |
65 | 14 |
|
66 | 15 | #### [Microsoft Azure operated by 21Vianet](#tab/azure-china)
|
67 | 16 |
|
68 |
| -> [!IMPORTANT] |
69 |
| -> Azure Arc agents require the following outbound URLs on `https://:443` to function. |
70 |
| -> For `*.servicebus.chinacloudapi.cn`, websockets need to be enabled for outbound access on firewall and proxy. |
71 |
| -
|
72 |
| -| Endpoint (DNS) | Description | |
73 |
| -| ----------------- | ------------- | |
74 |
| -| `https://management.chinacloudapi.cn` | Required for the agent to connect to Azure and register the cluster. | |
75 |
| -| `https://<region>.dp.kubernetesconfiguration.azure.cn` | Data plane endpoint for the agent to push status and fetch configuration information. | |
76 |
| -| `https://login.chinacloudapi.cn`<br/>`https://<region>.login.chinacloudapi.cn`<br/>`login.partner.microsoftonline.cn`| Required to fetch and update Azure Resource Manager tokens. | |
77 |
| -| `mcr.azk8s.cn` | Required to pull container images for Azure Arc agents. | |
78 |
| -| `https://gbl.his.arc.azure.cn` | Required to get the regional endpoint for pulling system-assigned Managed Identity certificates. | |
79 |
| -| `https://*.his.arc.azure.cn` | Required to pull system-assigned Managed Identity certificates. | |
80 |
| -|`https://k8connecthelm.azureedge.net` | `az connectedk8s connect` uses Helm 3 to deploy Azure Arc agents on the Kubernetes cluster. This endpoint is needed for Helm client download to facilitate deployment of the agent helm chart. | |
81 |
| -|`guestnotificationservice.azure.cn`<br/>`*.guestnotificationservice.azure.cn`<br/>`sts.chinacloudapi.cn`<br/>`https://k8sconnectcsp.azureedge.net` | For [Cluster Connect](../cluster-connect.md) and for [Custom Location](../custom-locations.md) based scenarios. | |
82 |
| -|`*.servicebus.chinacloudapi.cn` | For [Cluster Connect](../cluster-connect.md) and for [Custom Location](../custom-locations.md) based scenarios. | |
83 |
| -|`https://graph.chinacloudapi.cn/` | Required when [Azure RBAC](../azure-rbac.md) is configured. | |
84 |
| -|`*.arc.azure.cn` | Required to manage connected clusters in Azure portal.| |
85 |
| -|`https://<region>.obo.arc.azure.cn:8084/` | Required when [Cluster Connect](../cluster-connect.md) is configured. | |
86 |
| -|`dl.k8s.io`| Required when [automatic agent upgrade](../agent-upgrade.md#toggle-automatic-upgrade-on-or-off-when-connecting-a-cluster-to-azure-arc) is enabled. | |
87 |
| -|`quay.azk8s.cn`<br/>`registryk8s.azk8s.cn`<br/>`k8sgcr.azk8s.cn`<br/>`usgcr.azk8s.cn`<br/>`dockerhub.azk8s.cn/<repo-name>/<image-name>:<version>`|Container registry proxy servers for Azure China VMs.| |
| 17 | +[!INCLUDE [network-requirements-azure-china.md](network-requirements-azure-china.md)] |
0 commit comments