Livepatch client firewall configuration

On firewalled machines, canonical-livepatch needs access to two hostnames:

  • livepatch.canonical.com, port 443
  • livepatch-files.canonical.com, port 443

If livepatch client is enabled using Ubuntu Pro, additional access to contracts.canonical.com on port 443 will be required.

For snap installation, see snap network requirements.

Note: Previously patches were served via HTTP until switching over to HTTPS in ~Oct 2023.

1 Like

How to do this in “ufw” if this software only accepts ip numbers?.

The on-prem network access requirements were updated to use livepatch-files.canonical.com:443 instead of :80, but looks like this was missed.

It would also be nice to include a note that the protocol was changed (with an approximate date?).

cc @kian-parvin

Thanks @whershberger, this has now been fixed.