Egress
The integration makes outbound HTTPS calls only to the Kyberis API:
No other hosts are contacted at runtime. There are no webhooks and no inbound
connections; Kyberis never calls into your workspace.
- Classic compute. Allow egress to
api.kyberis.ai:443from cluster subnets, through your VPC or VNet firewall or egress appliance. - Serverless compute and Apps. If your account uses serverless egress
control, add
api.kyberis.aito the allowed destinations of the workspace’s network policy.
TLS
- HTTPS only. The client uses Python’s standard
urllibwith system CA trust and certificate verification on. There is no option in this integration to disable verification or use plainhttp. - If you route through a TLS-inspecting proxy, its CA must be in the cluster or app system trust store.
Timeouts and retries
Requests time out after 20 seconds and retry HTTP 429 and 5xx responses up to twice with short backoff, per the vendored client defaults. The batch helpers additionally stop calling the API after two consecutive whole-batch transport failures, and annotate the remaining rowstransport_error instead of hanging a job on a dead network..png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)