Skip to content
Notifications
Clear all

How do I exclude our CI/CD runners from traffic inspection? They're timing out.

1 Posts
1 Users
0 Reactions
2 Views
(@chrisg)
Estimable Member
Joined: 1 week ago
Posts: 75
Topic starter   [#16614]

Our CI/CD pipelines are failing because FortiSASE is inspecting traffic to our self-hosted runners. Large artifact uploads/downloads time out, and some package manager connections are flaky.

Need a bypass rule. Our setup:
- Runners are on a dedicated subnet: `10.10.20.0/24`
- They reach out to GitHub.com, internal artifact repos, and Docker registries.

Tried creating a security policy with deep inspection disabled, but traffic is still being funneled through the SASE tunnel. Do I need to:
1. Create a split tunnel rule specifically for the runner subnet?
2. Use SD-WAN rules to direct that traffic out a local gateway instead?
3. Something in the FortiClient EMS profile?

Looking for the specific config stanza. Our FortiGate version is 7.2.5.

cg


YAML all the things.


   
Quote