Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Egress identities
The address set a partner allowlists, the promise when it cannot serve, and private links
Today this runs on the management API
The egress_identities and private_links commands below are in the CLI's command list, but api.sylphx.com does not serve them.
A partner that allowlists you needs one thing: the addresses your traffic arrives from. An EgressIdentity declares them, one identity per region, so the set is something you write down and hand over rather than something you discover from the partner's logs.
#Declare an identity per region
spec.region is the whole spec: the region the addresses live in. Create one
identity for each region your project talks to a partner from, and give every
one of them to the partner.
sylphx network egress-identities create \
--parent orgs/acme/projects/shop \
--spec.region …The addresses are not something you choose. Read the identity back and
status.addresses lists the IPv4 and IPv6 addresses traffic leaves from:
sylphx network egress-identities get orgs/acme/projects/shop/egress_identities/egress-identityHand over the identity, not one address
A partner that allowlists a single address from that list has allowlisted a fraction of your traffic. Give them the addresses the identity reports, and re-read them after a change: the identity is the stable thing, and the list is what it currently reports.
#Traffic never leaves under an undeclared address
When the identity cannot serve, selected traffic is dropped. That is the point of declaring it: no request of yours arrives at a partner from an address the partner was not told about, so an allowlist on their side is a real boundary rather than a hopeful one. A dropped request is a refusal you can see, not a request that quietly came from somewhere else.
#Changing the set
region is the spec and the addresses follow from it, so an identity that names
another region reports that region's addresses. Read it back after the change
and hand the partner what it reports. Delete is destructive, so the CLI asks
before it runs, and the API takes an etag that must match the current one.
sylphx network egress-identities delete orgs/acme/projects/shop/egress_identities/egress-identity --yes#Private links
A PrivateLink is the other direction: a customer network reaching a Service without the public internet. Its spec names what is exposed and who may connect:
| Field | Type | What it is |
|---|---|---|
service | stringrequired | The Hosting Service exposed. |
region | stringrequired | The region of the link. |
allowed_consumers | string[]required | The customer network accounts allowed to connect. |
sylphx network private-links create \
--parent orgs/acme/projects/shop/envs/production \
--spec.service … \
--spec.region …status.state is the lifecycle: pending, established or rejected. When it
is established, status.endpoint_service is the endpoint the consumer connects
its network to — that is what you send them. An established link keeps carrying
traffic while the control plane is impaired; only changes wait.
A link lives under an environment, so it is created, changed and deleted like
any other resource in one: allowed_consumers is the field you change as a
partner's accounts change, and Delete is destructive.