PacketSafari

AI Endpoint Egress Approval

Approve access to customer-network and public AI endpoints without bypassing PacketSafari egress controls.

PacketSafari separates AI runtime configuration from network approval. Saving a provider never opens an outbound path automatically.

When approval is required

Approval is not required for localhost, 127.0.0.1, internal PacketSafari service names, or names ending in .svc.packetsafari.internal.

Approval is required for:

  • an AI server on another VM or appliance
  • a customer-network gateway on another host
  • a reverse proxy outside the PacketSafari container network
  • any internet-hosted provider

From the backend container's perspective, another host on the customer network is an external destination.

Approve an endpoint

After saving the provider, the admin UI displays the required host command. Run it from the PacketSafari deployment host:

packetsafari-ops egress approve-ai-host \
  --url "https://llm.company.example/v1"

The command updates the allowlist and restarts egress-ironproxy when needed. Return to the admin UI, run Test connection, then Refresh models.

Approval is hostname-based. PacketSafari approves a host such as llm.company.example, not individual /v1 paths.

To remove access:

packetsafari-ops egress remove-ai-host \
  --url "https://llm.company.example/v1"

Security behavior

Open Admin → Outbound access to inspect configured destinations, policy mode, and team AI approval status. This read-only page shows configuration, not proof that Iron Proxy has loaded it or that an endpoint is reachable. The listed ports describe intended use; the generated proxy allowlist matches hostnames, while application approvals additionally check the endpoint port and scheme.

Host operators can inspect approvals with packetsafari-ops egress list-ai-hosts. For repository-managed development environments, the equivalent python3 scripts/packetsafari_egress.py approve-ai-host --base-url ... helper remains available.

  • monitored application containers send outbound HTTP and HTTPS through egress-ironproxy
  • direct outbound bypasses are rejected
  • no-egress containers cannot open internet connections
  • public DNS recursion from application containers is denied
  • saving a new AI URL does not modify network policy
  • only the host approval command extends the allowlist

This prevents an application administrator from silently turning an arbitrary customer-network host into a new egress destination.