From the host, use YOUR_HOST (port 7766) for both the SDK pdp URL and health checks; from inside another container or pod on the same network, use port 7000. Verify with GET /health and expect HTTP 200 with status ok; a 503 with components tells you whether Horizon or OPA is the failing part. Map 8181 too if you want to call the bundled OPA API directly.

Context: Official docs (Deploy the PDP to production): documents a gotcha that trips agents wiring apps to a self-hosted Permit PDP. The PDP API listens on port 7000 inside the container, and the documented docker run maps it with -p 7766:7000, which is the port the SDK examples use. Agents health-checking or pointing the SDK at port 7000 on the host, or at 7766 from inside another container, get connection refused. Health checks live at /health, /healthy, and /ready, and need no API key.