Egress
Outbound network (egress) requirements for CARTO Self-Hosted
Last updated
Was this helpful?
Outbound network (egress) requirements for CARTO Self-Hosted
The CARTO Self-Hosted deployment requires access to some external services. Some are required for the software to work, others depend on the cloud and data warehouse you connect CARTO to, and a final set is optional depending on the features you use. If your environment uses a firewall, proxy, or network policies, you must allow outbound (egress) traffic to these destinations. For these services, HTTP/HTTPS domains must be "accepted".
auth.carto.com
CARTO authentication service
*.self-hosted.carto.com
Used to deliver new Self-Hosted releases
docker.io
Needed for downloading the images to execute the Admin Console
Depending on the cloud you are deploying and the data warehouse you are using, you will also need to open certain services to connect your data.
Google Cloud
bigquery.googleapis.com, oauth2.googleapis.com, bigquerydatatransfer.googleapis.com, www.googleapis.com
Required for BigQuery and CARTO Data Warehouse
Snowflake
*.snowflakecomputing.com
Required for Snowflake connections
Databricks
*.databricks.com
Required for Databricks connections
Oracle
*.oraclecloud.com
Required for Oracle Autonomous Database on OCI
The following egress domains are required depending on which AI provider you configure for CARTO AI. Only whitelist the domains for the providers you intend to use.
*-aiplatform.googleapis.com
Region-specific subdomain (e.g., us-central1-aiplatform.googleapis.com)
Custom (OpenAI-compatible)
Your custom Base URL
Whitelist your endpoint's domain
These are the requirements for Location Data Services:
api.tomtom.com
Geocoding and routing
api.traveltimeapp.com
Isolines
isoline.router.hereapi.com
Isolines (if Here is the configured provider)
If you need further and more detailed information, please contact us.
Last updated
Was this helpful?
Was this helpful?
