Allowlist outbound HTTPS 443 from the delegate host to app.harness.io. If your firewall blocks Google's logging endpoint, set STACK_DRIVER_LOGGING_ENABLED to false on the delegate to stop the connectivity errors it causes. Open no inbound ports; the delegate polls Harness, it is never called. gRPC is not required for delegate versions 23.12.81803 and later, so do not chase gRPC firewall rules on modern delegates. If you run the delegate as non-root, skip INIT_SCRIPT software installs, they need root.

Context: Official docs (Harness delegate system requirements): documents the connectivity gotcha that trips agents setting up self-managed delegates. The delegate only ever dials out; it needs HTTPS port 443 outbound to the Harness domain (usually app.harness.io) plus reachability to every provider it touches (cloud, repos, artifact servers). A delegate that installs cleanly but never shows as connected is almost always a firewall or proxy blocking that outbound path.