Monitor the services your firewall keeps private
Run one container inside your network and Checkly runs API, browser, and Playwright checks from there. Internal APIs, staging, the database behind the VPN: same checks, same alerts, same dashboards as the public side. Nothing opens inbound.
Trusted by teams whose most important services never touch the public internet
From public cloud to private network, one signal
Half your system is unreachable from the outside: internal APIs, admin tools, the staging cluster, services that only answer on the VPN. A private location puts a Checkly Agent next to them, so the checks that watch your public edge also watch what sits behind it.
Nothing gets opened inbound
The agent is a container that polls Checkly for work over an outbound connection to agent.checklyhq.com. No inbound ports, no allowlisting our IPs, no reverse tunnel. Corporate proxies and internal CA certificates are supported.
One platform, inside and out
The same check types, dashboards, alert channels, and status pages you use for public endpoints, now pointed at the intranet, the staging cluster, or the database behind the VPN. One signal for the whole system.
Defined in code, like everything else
A private location is a PrivateLocation construct in your Checkly CLI project. Assign it to a check or a whole group, review it in a pull request, and deploy it from CI. Full parity in the web app.
How a check runs inside your network
The Checkly Agent is a pull-based worker. It never listens for connections from Checkly, so your security team has nothing new to open and nothing new to allowlist.
The agent polls for jobs
Every agent in a private location opens an outbound connection to agent.checklyhq.com and asks for scheduled check runs. Checkly never connects in. Run it with Docker, Podman, or the official Helm chart on Kubernetes.
The check runs inside your network
The agent executes the check where it lives: the Playwright script, the API request, the TCP handshake. Internal hostnames resolve because the agent sits on your network, not ours.
Results report back to Checkly
Timings, assertions, screenshots, traces, and logs land in the same Checkly account as your public checks. Alerts fire through the same channels. If a location has no agent connected for 10 to 20 minutes, owners and admins get an email.
Requirements: a container runtime and outbound HTTPS to agent.checklyhq.com. Proxies are supported. Owner or Admin permissions to create a location.
Agent configuration →Good to know before you deploy
Private locations are included on the Team and Enterprise plans. Pending checks wait up to 6 minutes for a free agent, so size capacity for your peak. Playwright Check Suites need agent 6.0.3 or later on a container with 2 CPU cores and 4 GB of RAM. Heartbeat monitors are push-based and do not use locations.
One container. Every service covered.
Create a private location, run the agent, and point your first check at an internal hostname. The rest of your monitoring already knows what to do with it.