The two third-party hosts are being moved behind an Atlan-operated proxy, so
a future release will drop them from this list. Blocking them today costs
you nothing operationally - see below.
The minimum set
The first two hosts are the floor: without them, sign-in and sync do not work. The remaining hosts degrade a feature rather than break the app:- Blocking
k.atlan.devleaves updates dependent on the control-plane feed alone. - Blocking
releases.atlan.comstops updates entirely: the update check succeeds, but the download it points at lives on this host. - Blocking the Sentry and Segment hosts disables crash and usage reporting. The app is unaffected; Atlan support just sees less when you report a problem. No customer data flows to either: crash reports are scrubbed before send, and analytics carry product usage, not your content.
First-run install traffic
On first launch the app downloads its background sync runtime from the gateway origin (agentgateway.atlan.engineering), over TLS with an integrity
check. Plan for one ~50 MB download per device on first run, and budget
bandwidth accordingly for large fleets.