---
title: Network
description: The names a project answers on, the addresses its traffic leaves from, and the private paths into a Service.
type: tutorial
product: network
summary: Domains, certificates, routes, egress identities and private links, and what each one is for
updated: 2026-10-01
order: 0
---

<Callout tone="note" title="Today this runs on the management API">
Domains and hostnames are managed with `/v1/projects/{id}/domains` on the management API; the [Network quickstart](/docs/network/quickstart) shows how. The `domains` and `routes` collections in the [API reference](/docs/api/domains) are not served at api.sylphx.com.
</Callout>

Network is the layer between your project and everybody else's networks: the
names you answer on, the addresses your outbound traffic leaves from, and the
private paths into a Service. Five objects live here, and each answers one of
those questions.

## The five objects

<KeyValue
	items={[
		{ key: 'Domain', value: 'A name a project controls. Verified once, before anything uses it.' },
		{ key: 'Certificate', value: 'Covers the names Sylphx terminates itself. Read-only to you.' },
		{ key: 'Route', value: 'One exact host and path prefix, sent to one backend.' },
		{ key: 'Egress identity', value: 'A declared address set per region, for a third party to allowlist.' },
		{ key: 'Private link', value: 'A customer network reaching a Service without the public internet.' },
	]}
/>

## A Domain is a name you control

A [Domain](/docs/api/domains) is a name a project controls. It is verified once,
before any certificate or Route uses it, and verification is fail-closed:
nothing that serves traffic uses a name that has not been proven. A wildcard is
refused, so a Domain is always one exact name.

The id is the name with dots as dashes, so `shop.example.com` is the Domain
`shop-example-com`, while `spec.domain_name` is the name itself. Read it back
after verification and `status.verification` carries the record you published,
and `status.verified` says whether control was proven.

## A Certificate covers what Sylphx terminates

A [Certificate](/docs/api/certificates) covers the names Sylphx terminates
itself — the data door and the origin. It is read-only to you: the collection
has reads and no writes, and the private key is never read back. A customer
hostname on the web door is served by the edge without one, so a hostname of
your own does not need a Certificate of your own.

## A Route sends one address to one backend

A [Route](/docs/api/routes) sends one exact host and path prefix to one
backend. Every destination has its own Route; a wildcard grants no authority;
and overlapping host and path pairs are refused, so two backends cannot quietly
claim the same address. A backend is a Hosting Service, or a redirect with a
target and a status code.

## An egress identity is an address to allowlist

An [EgressIdentity](/docs/api/egress_identities) is a declared, stable address
set per region that your outbound traffic leaves from, so a third party can
allowlist you. `status.addresses` lists the IPv4 and IPv6 addresses traffic
leaves from. Traffic never leaves under an undeclared address: when the identity
cannot serve, selected traffic is dropped.

## A private link keeps the traffic off the public internet

A [PrivateLink](/docs/api/private_links) lets a customer network reach a
Service without the public internet. An established link keeps carrying traffic
while the control plane is impaired; only changes wait. `status.endpoint_service`
is the endpoint the consumer connects its network to.

## Names and ids

<KeyValue
	items={[
		{ key: 'Domain', value: 'dom_<cell><ulid>', mono: true },
		{ key: 'Certificate', value: 'crt_<cell><ulid>', mono: true },
		{ key: 'Route', value: 'rte_<cell><ulid>', mono: true },
		{ key: 'Egress identity', value: 'egr_<cell><ulid>', mono: true },
		{ key: 'Private link', value: 'plk_<cell><ulid>', mono: true },
	]}
/>

A resource's name is a path, and the same path works in the API, the CLI and the
console. A Domain and an EgressIdentity belong to a project; a Route and a
PrivateLink belong to an environment inside one.

`network:read` covers the reads. Everything that changes a Domain, a Route, an
egress identity or a private link needs `network:write`.

<RelatedDocs
	links={[
		{
			href: '/docs/network/quickstart',
			label: 'Quickstart',
			description: 'Point a hostname of your own at a Service.',
		},
		{
			href: '/docs/network/domains',
			label: 'Domains',
			description: 'Creating a name, proving it, and what deletion is fenced by.',
		},
		{
			href: '/docs/network/routes',
			label: 'Routes',
			description: 'One host and path prefix to one backend, and what a change does to live traffic.',
		},
		{
			href: '/docs/network/egress',
			label: 'Egress identities',
			description: 'Declaring the addresses your traffic leaves from, and private links.',
		},
	]}
/>
