Egress configurations - Cortex Gateway Admin Guide - Cortex - Cortex - Security Operations

Cortex Gateway Administrator Guide

Product
Cortex
Creation date
2023-03-23
Last date published
2026-05-03
Category
Cortex Gateway Admin Guide

The outgoing communication between tenants and external services is defined either by Cortex or by the user. Using the Egress Configurations feature in the Cortex Gateway, the user can define, manage and approve a tenant's outgoing communication flow, providing greater control over outgoing traffic. Refer to Flows/Path for detailed information on which flows are available for you to create a path for your tenant.

Important

Only Account Admin and Instance Admin can submit a request on behalf of a user. Only users with these roles can view the Egress Configurations option in the Gateway.

The Account Admin can view all the tenants from the account where requests have been submitted, and the Instance Admin can view all the requests that have been submitted for their tenant.

Egress configuration options

In Cortex Gateway, you can use the Egress Configurations for the following options:

  • You can create a path.

  • You can remove a request that's been approved.

  • You can filter by flow.

Egress configuration parameters

After creating a path for your tenant, it is added to the Egress configurations table.

Parameter

Description

Requester

The user who is creating the path.

Only Account Admin and Instance Admin can submit a request on behalf of a user.

Requester Email

The email of the requester.

Approver

The approver is the Account Admin or Instance Admin.

Approver Email

The email of the approver.

Route ID

A unique identifier associated with the path.

Status

The status of the egress path, which can be:

  • Approved

  • Removed

Date of Request

The date the path was created.

Updated

The date the path was updated.

Flows/Path

The table includes the list of flows that require egress configuration paths before enabling the outgoing traffic.

Flow

Path

Example

GitHub Server

<host>

Enter the domain name or IP address of the GitHub instance.

github.com

GitHub (Code Scanning)

<repo_owner>

Enter the owner or organization name of the repository in GitHub.

alicesmith

GitLab Self Managed

<host>

Enter the domain name or IP address of the GitLab instance.

gitlab.com

GitLab (Code Scanning)

<project_name>

Enter the project name within GitLab to allow access.

myproject

BitBucket (Code Scanning)

<workspace>

Enter the workspace of your project or repository of the BitBucket application.

engineering-team

BitBucket Data Center

<host>

Enter the server name of where the BitBucket application is running.

bitbucket.com

Azure DevOps (Code Scanning)

<org_name>

Enter the name of the organization of the Azure Repos instance.

myprojectteam

TF Run Task Cloud

<host>

Enter the domain name or IP address of the TF Run Task Cloud instance.

tfruntask.com

TF Run Task Enterprise

<host>

Enter the domain name or IP address of the TF Run Task Enterprise instance.

tfruntask.com

External Storage: S3-compatible

<host>

Enter the domain name or IP address of the External Storage: S3-compatible

s3browser.com

External Storage: AWS S3

<bucket_name>

Enter the name of the AWS S3 bucket to allow access.

my-example-bucket

Snowflake

<host>

Enter the host or domain name of the Snowflake account to which you are connecting.

mycompany.snowflakecomputing.com

SonarQube

<host>

Enter the host address or domain of the SonarQube instance to which you are connecting.

sonarqube.mycompany.com

Webhook

<host>

Enter the host name of the Webhook endpoint.

webhook.mycompany.com

External storage: AWS SQS

<queue_name>

Enter the name of the AWS SQS queue.

my-example-queue

Splunk

<host>

Enter the host or domain name of the Splunk instance.

splunk.mycompany.com

Submit a new path

Remove a path