Q: A pipeline works on a Microsoft-hosted agent but fails with a connection timeout on a self-hosted agent. How would you isolate the issue?
Network and proxy isolation framework for diagnosing connection timeouts on self-hosted Azure DevOps agents operating inside corporate VNets.
#Azure DevOps #Networking #Self-Hosted Agents #VNet #Firewall
🎙️ Candidate Opening & Architectural Context
"Microsoft-hosted agents have open outbound internet access, while self-hosted agents live inside restricted Azure VNets with corporate Network Security Groups (NSGs), route tables, and outbound proxies. The issue is almost always VNet routing, firewall egress, or proxy configuration."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1
Verify Outbound Network Security Group (NSG) Rules
Check if the subnet hosting the self-hosted VM has an NSG rule blocking outbound port 443 to the target service (e.g., GitHub, Azure Artifacts, Docker Hub, or Azure Resource Manager).
# Test connectivity directly from the self-hosted agent shell
nc -zv dev.azure.com 443
curl -Iv https://pkg.actions.githubusercontent.com
2
Check Corporate Proxy & Environment Variables
If your organization routes traffic through an egress proxy (e.g., Squid, Zscaler), ensure HTTP_PROXY, HTTPS_PROXY, and NO_PROXY are defined in the agent's .env file and that TLS inspection certificates are installed.
3
Validate Azure Private DNS Zone Resolution
If accessing internal resources like Azure Container Registry (ACR) with Private Endpoints, verify the self-hosted agent VM resolves the private IP address rather than the public IP.
nslookup myacr.azurecr.io
# Expected: 10.x.x.x private IP, NOT public 20.x.x.x
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Self-hosted agents fail due to VNet boundary constraints. Test port 443 egress via nc/curl, check HTTP_PROXY environment variables, and verify Private Endpoint DNS resolution."
⚡ 60-Second Elevator Pitch Talking Points
- Test outbound connectivity from the agent VM using curl -Iv and nc -zv on port 443.
- Verify Network Security Groups (NSGs) and Azure Firewall egress filtering rules.
- Inspect HTTP_PROXY, HTTPS_PROXY, and corporate CA certificate trust in the agent .env file.
- Confirm Private DNS zone resolution for internal ACR and Key Vault private endpoints.
Advertisement