Cloud & Deployment Shapes
What network traffic crosses boundaries in Catalyst deployments?
By default, no core Catalyst network traffic crosses private network boundaries in standard deployments. Core durable execution state and workflow orchestration remain within your fully controlled, isolated private network; only activated LLM inference or third-party tool integrations require explicitly configured outbound public network access. Unconfigured external service calls may inadvertently expose sensitive internal workflow data without proper pre-deployment security policies and network controls.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Cloud & Deployment Shapes
Can I run Catalyst within my private VPC or on-prem network?
Overview of deployment options for Diagrid Catalyst agent workflows within private, customer-controlled cloud network environments.
- Cloud & Deployment Shapes
How do I deploy Catalyst for hybrid cloud agent workflows?
IT teams practical guidance for deploying Diagrid Catalyst agent workflows via CNCF Dapr using secure tunnels for state synchronization across hybrid cloud
- Cloud & Deployment Shapes
How do managed and self-hosted Catalyst deployments differ?
Detailed comparison of operational overhead and infrastructure control tradeoffs for engineering teams evaluating managed