Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Network

Domains, certificates, routes, egress identities and private links, and what each one is for

Today this runs on the management API

Domains and hostnames are managed with /v1/projects/{id}/domains on the management API; the Network quickstart shows how. The domains and routes collections in the API reference are not served at api.sylphx.com.

Network is the layer between your project and everybody else's networks: the names you answer on, the addresses your outbound traffic leaves from, and the private paths into a Service. Five objects live here, and each answers one of those questions.

#The five objects

Domain
A name a project controls. Verified once, before anything uses it.
Certificate
Covers the names Sylphx terminates itself. Read-only to you.
Route
One exact host and path prefix, sent to one backend.
Egress identity
A declared address set per region, for a third party to allowlist.
Private link
A customer network reaching a Service without the public internet.

#A Domain is a name you control

A Domain is a name a project controls. It is verified once, before any certificate or Route uses it, and verification is fail-closed: nothing that serves traffic uses a name that has not been proven. A wildcard is refused, so a Domain is always one exact name.

The id is the name with dots as dashes, so shop.example.com is the Domain shop-example-com, while spec.domain_name is the name itself. Read it back after verification and status.verification carries the record you published, and status.verified says whether control was proven.

#A Certificate covers what Sylphx terminates

A Certificate covers the names Sylphx terminates itself — the data door and the origin. It is read-only to you: the collection has reads and no writes, and the private key is never read back. A customer hostname on the web door is served by the edge without one, so a hostname of your own does not need a Certificate of your own.

#A Route sends one address to one backend

A Route sends one exact host and path prefix to one backend. Every destination has its own Route; a wildcard grants no authority; and overlapping host and path pairs are refused, so two backends cannot quietly claim the same address. A backend is a Hosting Service, or a redirect with a target and a status code.

#An egress identity is an address to allowlist

An EgressIdentity is a declared, stable address set per region that your outbound traffic leaves from, so a third party can allowlist you. status.addresses lists the IPv4 and IPv6 addresses traffic leaves from. Traffic never leaves under an undeclared address: when the identity cannot serve, selected traffic is dropped.

A PrivateLink lets a customer network reach a Service without the public internet. An established link keeps carrying traffic while the control plane is impaired; only changes wait. status.endpoint_service is the endpoint the consumer connects its network to.

#Names and ids

Domain
dom_<cell><ulid>
Certificate
crt_<cell><ulid>
Route
rte_<cell><ulid>
Egress identity
egr_<cell><ulid>
Private link
plk_<cell><ulid>

A resource's name is a path, and the same path works in the API, the CLI and the console. A Domain and an EgressIdentity belong to a project; a Route and a PrivateLink belong to an environment inside one.

network:read covers the reads. Everything that changes a Domain, a Route, an egress identity or a private link needs network:write.