Halo is moving its application servers to AWS Elastic Kubernetes Service (EKS), a containerised hosting platform, over the coming months. Halo says the move will make the platform faster and more resilient, and give admins more control over when upgrades happen.
Most of the change is invisible to the people using Halo. A few parts are not, and they land on your IT and network team rather than your service desk. Here's what's changing, when, and what to check.
When it happens
The change starts in the Beta channel and reaches Stable in the first Stable release of 2027. If you're on Stable, nothing changes for you today.
What gets better
Faster scaling. Application builds now run in containers on Kubernetes. Halo quotes around a 95% reduction in the time it takes to scale out, along with more consistent deployments and easier rollbacks.
Faster load times worldwide. AWS CloudFront will cache content at edge locations closer to your users. That matters most for teams spread across countries.
Smaller responses. API and web responses are compressed in transit, so less data travels on every page and every API call.
Automations get their own engine. The automations engine moves into its own Kubernetes microservice, taking load off the main SQL database. During the transition its data syncs back to SQL Server, and it will eventually live in DynamoDB.
A dedicated bulk email service. A new service handles high volume campaign email, with better deliverability and throughput.
More control over upgrades. Admins will get a scheduled upgrade window before each release, with on demand deployment to follow. At first, the admin area shows version history only; the deploy buttons come later.
What your IT team needs to check
These are the points that need someone outside the Halo admin team. Worth sharing this list with your IT and network owners now.
Outbound IP addresses are changingAction
Integrations, outbound mail and web requests from Halo will come from new IP ranges. If your firewall or mail relay allow lists Halo's current addresses, those rules need updating. Halo has published the new ranges, by region, on guide 1446. Bookmark it, as that's where any further changes will appear. Inbound traffic is not affected.
Certificates move to HaloAction
If you reach Halo on your own custom domain, Halo will now manage the certificate, including where it's currently issued by Amazon. Halo will send you DNS validation records to add. Keep your existing DNS records until you're on version 2.252. Until the DNS changes are made, custom domain instances stay on version 2.250, the 2026 final release.
API calls need a User-Agent headerAction
Every call to the Halo API must now include a User-Agent header. Older or custom scripts that don't send one will need updating.
Reports that read automation tables directlyAction
If any custom report reads straight from the Automation, AutomationIteration, AutomationVariable or WebhookEvent tables, talk to your Halo contact to plan the transition.
IP access restrictions move into HaloNo action yet
IP access restrictions become an admin setting inside the Halo application. Nothing to do for now.
Our read
The certificate and User-Agent points are the ones most likely to catch teams out. DNS on a custom domain usually belongs to someone outside the Halo admin team, and scripts written years ago rarely send a User-Agent header. Neither is a big job, but both are easy to miss. Now, while the change is still in Beta, is the time to name an owner for each.
For questions about your own instance, your Halo Customer Success Manager is the first stop, and Halo posts migration updates on its status page. If you'd like help working out which integrations, scripts and reports this touches in your Halo, Allied ESM can scope that with you. Get in touch.