기술 자료

​
​

Development

User Acquisition

Monetization

산업 분야

Self-Hosted Deployment

Amazon Web Services

Microsoft Azure

On premises

vpctl

Self-Hosted Deployment

이 페이지는 선택한 언어로 제공되지 않습니다.
​
​
Self-Hosted Deployment
  • Overview
  • Amazon Web Services
  • Microsoft Azure
    • Installation
      • Deployment modes
      • Deployment through Azure Marketplace
        • Infrastructure overview
        • Prerequisites
        • Deployment
        • Postdeployment
        • Firewall rules for the outbound internet access
      • Manual deployment
    • Maintenance
  • On premises
  • Administration
  • Security
  • vpctl
  1. Self-Hosted Deployment (previously called Unity Virtual Private Cloud)
  2. Self-Hosted Deployment in Microsoft Azure
  3. Installation

Firewall rules for the outbound internet access

If you want to restrict outbound access, configure the required firewall rules
읽는 시간 1분
최근 업데이트: 한 달 전

If you want to restrict outbound access, implement these firewall rules:
  • Generic outbound configuration for the Azure Kubernetes Service (AKS) cluster, to lock down the traffic that leaves the AKS subnet. Refer to the required outbound network rules and fully qualified domain names (FQDNs) in the Microsoft documentation.
  • Access from the AKS cluster to the Azure Container Registry (ACR) that contains the container images of Self-Hosted Deployment:
    • Login server:
      https://uccmpprivatecloud.azurecr.io
    • Data plane:
      • If dedicated data endpoints aren't enabled:
        • https://*.blob.core.windows.net
      • If dedicated data endpoints are enabled:
        • https://uccmpprivatecloud.eastus.data.azurecr.io
        • https://uccmpprivatecloud.northeurope.data.azurecr.io
  • Access from the AKS cluster, for AKS extension agents such as GitOps:
    • https://*.dp.kubernetesconfiguration.azure.com
  • Access from the AKS cluster to the enterprise identity provider, which Keycloak connects to in order to retrieve user tokens via a backchannel. Specific FQDNs depend on the IdP vendor, for example, it is
    https://login.microsoftonline.com
    for Microsoft Entra ID.
  • Access from the PostgreSQL servers to Entra ID, for traffic that leaves the PostgreSQL subnet. Refer to the description of private access networking for Azure Database for PostgreSQL flexible server in the Microsoft documentation.
    • All traffic to the
      AzureActiveDirectory
      service tag.

Copyright © 2026 Unity Technologies
법률 정보개인정보 처리방침쿠키Documentation Terms of Use개인 정보 판매 또는 공유 금지개인정보 보호 선택(쿠키 설정)

'Unity', Unity 로고 및 기타 Unity 상표는 미국 및 기타 지역 내 Unity Technologies 또는 그 계열사의 상표 또는 등록상표입니다(자세한 내용은 여기에서 확인하세요). 기타 명칭 또는 브랜드는 해당 소유자의 상표입니다.

일부 페이지는 편의를 위해 기계 번역되었으며 부정확한 내용이 있을 수 있습니다. 정보가 상충되는 경우, 영어 버전을 우선으로 참조하세요.


    이 페이지의 문제 보고