服务域名、GHE.com 与语音允许列表
区分客户端出站、按套餐路由、报告下载及 cloud agent 内置防火墙。
公司防火墙或代理需要允许认证与 Copilot 服务流量,用户客户端也要配置正确的代理和证书。网络服务允许列表与 cloud agent 运行环境中的防火墙是不同层级,不应直接互换。
GitHub.com 基础域名
官方建议通过 /meta 查询当前所需通配域名:
gh api meta -q '.domains | .website, .copilot'另需允许根域 github.com,它不被 *.github.com 覆盖,也不在上述查询结果中;API 的 domains.actions 另有它。结果只覆盖多数服务,报告回退等还有额外域名。
具体服务
| 用途 | 官方列出的 URL |
|---|---|
| 登录 | https://github.com/login/*、https://github.githubassets.com、https://avatars.githubusercontent.com |
| GitHub 上的 Copilot | https://github.com/copilot/* |
| EMU 认证 | https://github.com/enterprises/YOUR-ENTERPRISE/* |
| 用户管理 | https://api.github.com/user、https://api.github.com/copilot_internal/* |
| 分析遥测 | https://collector.github.com/* |
| 客户端遥测 | https://copilot-telemetry.githubusercontent.com/telemetry |
| 客户端实验 | https://default.exp-tas.com |
| 建议服务 | https://copilot-proxy.githubusercontent.com、https://origin-tracker.githubusercontent.com |
| 通用建议 API | https://*.githubcopilot.com/* |
如果使用按套餐路由,不要加入通用 *.githubcopilot.com 放行规则;应按需要允许 Business / Enterprise 子域并处理个人套餐流量。
用量报告下载
主域为 https://copilot-reports.github.com。官方还要求为回退下载场景允许:
https://copilot-reports-*.b01.azurefd.net:从 Azure Front Door CDN 下载。https://usagereports*.blob.core.windows.net:直接从 Azure Blob Storage 下载。
这两个回退域名不在上述 /meta 查询覆盖中。能登录 Copilot 但不能下载报告时,应核对它们,而不是仅反复刷新报告页面。
GHE.com
数据驻留企业使用 https://*.SUBDOMAIN.ghe.com 和 https://SUBDOMAIN.ghe.com,把 SUBDOMAIN 换成企业 slug。若使用 public code detection,还需要 https://origin-tracker.githubusercontent.com 检查 GitHub.com 的公共代码。
其余 GitHub.com 服务域名不按原样要求:服务有企业专属子域,例如 https://copilot-proxy.SUBDOMAIN.ghe.com/;客户端实验在 GHE.com 关闭,不需要 default.exp-tas.com;个人计划和套餐路由也不适用。
CLI 与 app 语音
语音功能通过 Foundry Local 在本机运行 speech-to-text 模型,但查询目录和下载模型仍需要出站访问:
| 域名 | 用途 |
|---|---|
https://ai.azure.com | 模型目录 |
https://api.catalog.azureml.ms | 查找适合下载的 Azure 区域 |
https://*.api.azureml.ms | 区域模型目录端点 |
https://amlwlrt4*.blob.core.windows.net | 区域 Blob 模型下载 |
下载域名中的通配匹配不同区域的 storage account,不能固定成某一用户当前看到的单一账户。
与其他网络层配合
编辑器本身还可能有额外出站要求,例如 VS Code 的 vscode.dev。代理类型、环境变量优先级、Kerberos 和证书见IDE 网络设置。
Cloud agent 另有默认开启的推荐允许列表,覆盖常见系统仓库、语言包仓库、容器仓库、证书机构和 Playwright 浏览器下载。该运行环境列表不是公司客户端的必要服务列表,配置见云端防火墙。官方完整主机清单会变化,不把本页列出的客户端域名当作它的替代品。