Skip to content

Prerequisites for Private Locations

Infrastructure Workflow

  1. The locally deployed Private Location connects to the Escape platform.
  2. When a scan is initiated, Escape sends requests to the Private Location service rather than directly to your servers.
  3. The Private Location forwards the requests to your internal applications.
  4. Scan results are then returned to Escape for reporting and analysis.

Diagram of Private Location Infrastructure:

Escape Private Locations

Resource Requirements

Resource requirements depend on traffic. The Helm chart defaults to 1 vCPU and 2 GiB RAM for both requests and limits. These defaults are configurable: set container.resources.cpu and container.resources.memory to match your workload. See Helm Values.

Connectivity Model

Deploy the Private Location within your organization's infrastructure, for example on an EC2 instance. It acts as a proxy between your internal systems and the Escape platform. The container initiates an outbound SSH connection to Escape, receives scan jobs over this tunnel, and sends results back through the same channel. Keep it private and allow the egress connections described below. This outbound connection model works without inbound internet access, an API Gateway, or a load balancer.

Firewall Configuration

Private Locations require specific firewall rules to establish outbound connections to Escape's infrastructure. For detailed information about required egress connections, see the Firewall Configuration documentation.

DNS Resolution

Internal target hostnames are resolved using the host or container's configured DNS resolvers (/etc/resolv.conf on Linux and macOS, Windows adapter settings on Windows). Ensure these resolvers can resolve your internal zones and are reachable on UDP port 53.

Configure an internal DNS resolver for private names. If no system resolver is available, DNS queries can fall back to public resolvers.

Kubernetes Integration and RBAC

By default, the Helm chart creates a ServiceAccount, a cluster-wide ClusterRole, and a ClusterRoleBinding. The role grants get and list on namespaces, services, networking.k8s.io/ingresses, and Istio virtualservices, gateways, and destinationrules.

The Private Location automatically registers a Kubernetes integration using the location name. To disable the integration and omit these RBAC resources, install or upgrade the chart with --set ESCAPE_K8S_INTEGRATION=false.

Organization Scope and Permissions

Private Locations are shared across all projects in your organization. Creating, editing, and deleting them requires the global Admin permission.