Connectivity
Private Locations Availability & Connectivity¶
Does the Private Location Restart Automatically if It Disconnects?¶
The agent retries its SSH connection when it disconnects. Docker Compose's restart: always restarts a container only after its process exits. It doesn't restart a running container just because the location is disconnected.
The Helm chart combines a scheduled 24h restart with a liveness probe. For Docker Compose and other custom deployments, set HEALTH_CHECK_PORT, monitor /health, and restart the container if it reports 503. See Environment Variables.
Does the Private Location Turn Off After a Period of Inactivity?¶
The Private Location stays active between scans while connected to Escape. It sends regular heartbeats to report its connection status and remains ready for incoming scan requests.
At startup, the agent exits with an error if it can't register with the Escape API, including when the API is unreachable or the API key is invalid. ESCAPE_API_KEY must be in UUID format. Check startup errors if your container repeatedly restarts.
After registration, the agent keeps retrying a disconnected SSH tunnel, but exits if a later registration attempt rejects its API key. A configured restart interval or your orchestrator can still restart the process. Helm configures a 24h restart interval by default.
What Type of Traffic Goes Through Port 80?¶
The current escape-cli Private Location agent connects to the Escape platform over the SSH tunnel on port 2222 (see Firewall Configuration). It doesn't use port 80.
How Are Internal Hostnames Resolved?¶
Internal target hostnames are resolved using the Private Location host or container's configured DNS resolvers. Ensure the location can resolve your internal zones and reach those resolvers. See DNS Resolution.
Troubleshooting¶
If connectivity issues are experienced or troubleshooting is needed for a Private Location, the following steps should be followed:
- Verify deployment configuration: The deployment configuration should be checked to ensure the API key is correctly set and hasn't expired
- Review firewall settings: Firewall settings should be verified to allow the necessary outbound connections to the Escape platform
- Check SSL/TLS configuration: The SSL/TLS configuration should be reviewed to ensure certificates are valid and properly configured for secure connections
- Analyze logs: Logs should be monitored and analyzed using the logging and monitoring tools to identify specific error patterns or connection issues
- Contact support: If issues persist after following the above steps, the support team should be contacted with relevant log excerpts and configuration details for further assistance