Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Network
Domains, certificates, routes, egress identities and private links, and what each one is for
Today this runs on the management API
Domains and hostnames are managed with /v1/projects/{id}/domains on the management API; the Network quickstart shows how. The domains and routes collections in the API reference are not served at api.sylphx.com.
Network is the layer between your project and everybody else's networks: the names you answer on, the addresses your outbound traffic leaves from, and the private paths into a Service. Five objects live here, and each answers one of those questions.
#The five objects
- Domain
- A name a project controls. Verified once, before anything uses it.
- Certificate
- Covers the names Sylphx terminates itself. Read-only to you.
- Route
- One exact host and path prefix, sent to one backend.
- Egress identity
- A declared address set per region, for a third party to allowlist.
- Private link
- A customer network reaching a Service without the public internet.
#A Domain is a name you control
A Domain is a name a project controls. It is verified once, before any certificate or Route uses it, and verification is fail-closed: nothing that serves traffic uses a name that has not been proven. A wildcard is refused, so a Domain is always one exact name.
The id is the name with dots as dashes, so shop.example.com is the Domain
shop-example-com, while spec.domain_name is the name itself. Read it back
after verification and status.verification carries the record you published,
and status.verified says whether control was proven.
#A Certificate covers what Sylphx terminates
A Certificate covers the names Sylphx terminates itself — the data door and the origin. It is read-only to you: the collection has reads and no writes, and the private key is never read back. A customer hostname on the web door is served by the edge without one, so a hostname of your own does not need a Certificate of your own.
#A Route sends one address to one backend
A Route sends one exact host and path prefix to one backend. Every destination has its own Route; a wildcard grants no authority; and overlapping host and path pairs are refused, so two backends cannot quietly claim the same address. A backend is a Hosting Service, or a redirect with a target and a status code.
#An egress identity is an address to allowlist
An EgressIdentity is a declared, stable address
set per region that your outbound traffic leaves from, so a third party can
allowlist you. status.addresses lists the IPv4 and IPv6 addresses traffic
leaves from. Traffic never leaves under an undeclared address: when the identity
cannot serve, selected traffic is dropped.
#A private link keeps the traffic off the public internet
A PrivateLink lets a customer network reach a
Service without the public internet. An established link keeps carrying traffic
while the control plane is impaired; only changes wait. status.endpoint_service
is the endpoint the consumer connects its network to.
#Names and ids
- Domain
- dom_<cell><ulid>
- Certificate
- crt_<cell><ulid>
- Route
- rte_<cell><ulid>
- Egress identity
- egr_<cell><ulid>
- Private link
- plk_<cell><ulid>
A resource's name is a path, and the same path works in the API, the CLI and the console. A Domain and an EgressIdentity belong to a project; a Route and a PrivateLink belong to an environment inside one.
network:read covers the reads. Everything that changes a Domain, a Route, an
egress identity or a private link needs network:write.