Overview

This deployment option is designed for organizations with strict network security policies that allow selective internet connectivity through whitelist/allowlist rules.

Key Benefit: Consolidates all Quix platform dependencies into a single mirror registry, eliminating the need to whitelist multiple public registries and their complex CDN redirect chains (particularly Docker Hub).

Required Network Access

Container Registry

QuixAI

Inbound IP addresses

These are the IP addresses where Anthropic services receive incoming connections.

IPv4

IPv6

Outbound IP addresses

These are the stable IP addresses that Anthropic uses for outbound requests (for example, when making MCP tool calls to external servers).

IPv4

Per https://platform.claude.com/docs/en/api/ip-addresses

Note: Technically only the QuixAI pods need to access these IPs, so network policy may be helpful, but DevSessions requiring it in the future would complicate that. If anyone should ask.

Common Requirements

For authentication, monitoring, developer services, and DNS requirements shared across all Quix deployments, see Common Network Requirements.

Support

For questions about whitelisted deployments, contact Quix support.