| Permit Orka Network | ANY | | NTP | | Client and Administration requirement for DNS and NTP services |
| Permit Orka Network | ANY | | DNS | | Client and Administration requirement for DNS and NTP services |
| Permit Orka Network | ANY | | DNS over HTTPS | | Client and Administration requirement for DNS and NTP services |
| Permit Orka Network | 207.254.1.172 | | | | |
| 207.254.72.172 | | | | | |
| 208.83.0.22 | | | | | |
| 199.19.85.74 | TCP 2049 | | | NFS needed for Remote ISO shares. Set per market; where client download ISO files from MacStadium: | |
| ATL - 207.254.1.172, | | | | | |
| LSV - 207.254.72.172, | | | | | |
| DUB - 208.83.0.22, | | | | | |
| SJC - 199.19.85.74 | | | | | |
| Permit Orka Network | | | HTTP | mirror.math.princeton.edu | FCOS Linux Internal Packages: for the environment during the provisioning process; where dependencies are pulled - administration purposes; not client usage |
| Permit Orka Network | | | HTTPS | hooks.slack.com | Action Runner (typically 10.221.188.10) to update Slack - administration purposes; not needed for client use |
| Permit Orka Network | | | HTTPS | us-west2-docker.pkg.dev | Needed for Administrative purpose; in case POD needs to repull image; for client; if they are deploying Intel VMs then this rule is needed. |
| Permit Orka Network | | | HTTPS | | |
| Web Applications | | | | | |
| SSL Client | production.cloudflare.docker.com | Requirement for Docker certificates | | | |
| Permit Orka Network | | | HTTPS | hub.docker.com | Administration rule requirement: Requirement for Docker Container Images |
| Permit Orka Network | | | | k8s.gcr.io | Administration rule reuirement; Requirement for K8S Container Images |
| Permit Orka Network | | TCP 10259 | | | |
| TCP 2379 | | | | | |
| TCP 2380 | | | | | |
| TCP 6443 | | registry.k8s.io | Administration traffic; client use not necessary: review rules | | |
| Permit Orka Network | | | HTTPS | pkgs.k8s.io | Administration Stacks requirement |
| Permit Orka Network | | | HTTPS | k8s.io | catch-all for the URL |
| Permit Orka Network | | | HTTP | | |
| HTTPS | get.helm.sh | Administration Requirement for K8 Stack | | | |
| Permit Orka Network | | | HTTPS | projectcalico.org | Administration Requirement for K8 Stack |
| Permit Orka Network | | | HTTPS | updates.cdn-apple.com | Client and Administration requirement - especially based on VMs OS |
| Permit Orka Network | | | HTTPS | configuration.apple.com | Client and Administration requirement - especially based on VMs OS |
| Permit Orka Network | | | HTTPS | adc.apple.com | Client and Administration requirement - especially based on VMs OS |
| Permit Orka Network | | | HTTPS | swscan.apple.com | Client and Administration requirement - especially based on VMs OS |
| Permit Orka Network | | | HTTPS | apple.com | Catchall for any other apple site that appeared as blocked during the earlier POC session |
| Permit Orka Network | | | HTTPS | formulae.brew.sh | Client and Administration requirement - dependency for MacOs package manager |
| Permit Orka Network | | | Amazon Web Services | | Administration Requirement for ORKA Stack |
| Permit Orka Network | | | HTTPS | mimir.nap.macstadium.com | Administration Requirement for monitoring Stack |
| Permit Orka Network | | | HTTPS | grafana.orka.dev | Administration Requirement for monitoring Stack |
| Permit Orka Network | | | HTTPS | dns-challenge-validator.orka.dev | Client and Administration Requirement for Certificate Validation |
| Permit Orka Network | | | HTTPS | loki.orka.dev | Administration Requirement for monitoring Stack |
| Permit Orka Network | | | HTTPS | orka.dev | Catch-all for the URL |
| Permit Orka Network | | | HTTPS | pypi.org | Administration Requirement for Docker Authentication |
| Permit Orka Network | | | HTTPS | pypi.org | Administration Requirement for Docker Authentication |
| Permit Orka Network | | | HTTPS | auth.docker.io | Administration Requirement for Container images |
| Permit Orka Network | | | HTTPS | charts.jetstack.io | Administration Requirement for Container images |
| Permit Orka Network | | | HTTPS | fedoraproject.org | Administration Requirement for Container images |
| Permit Orka Network | | | HTTPS | edge.kernel.org | Administration Requirement for Container images |
| Permit Orka Network | | | HTTPS | files.pythonhosted.org | Administration Requirement for python dependencies |
| Permit Orka Network | | | HTTPS | gchr.io | Administration Requirement for Container and Client images |
| Permit Orka Network | | | Github | | Client and Admin Requirement for OCI |
| Permit Orka Network | | | HTTPS | quay.io | Administration Requirement for Container and Client images |
| Permit Orka Network | | | HTTPS | packages.cloud.google.com | Administration Requirement for Container images |
| Deny Orka Network | ANY | | | | A catch all deny rule if traffic doesn’t match the above |