Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Egress identities

The address set a partner allowlists, the promise when it cannot serve, and private links

Today this runs on the management API

The egress_identities and private_links commands below are in the CLI's command list, but api.sylphx.com does not serve them.

A partner that allowlists you needs one thing: the addresses your traffic arrives from. An EgressIdentity declares them, one identity per region, so the set is something you write down and hand over rather than something you discover from the partner's logs.

#Declare an identity per region

spec.region is the whole spec: the region the addresses live in. Create one identity for each region your project talks to a partner from, and give every one of them to the partner.

Shell
sylphx network egress-identities create \
  --parent orgs/acme/projects/shop \
  --spec.region …

The addresses are not something you choose. Read the identity back and status.addresses lists the IPv4 and IPv6 addresses traffic leaves from:

Shell
sylphx network egress-identities get orgs/acme/projects/shop/egress_identities/egress-identity

Hand over the identity, not one address

A partner that allowlists a single address from that list has allowlisted a fraction of your traffic. Give them the addresses the identity reports, and re-read them after a change: the identity is the stable thing, and the list is what it currently reports.

#Traffic never leaves under an undeclared address

When the identity cannot serve, selected traffic is dropped. That is the point of declaring it: no request of yours arrives at a partner from an address the partner was not told about, so an allowlist on their side is a real boundary rather than a hopeful one. A dropped request is a refusal you can see, not a request that quietly came from somewhere else.

#Changing the set

region is the spec and the addresses follow from it, so an identity that names another region reports that region's addresses. Read it back after the change and hand the partner what it reports. Delete is destructive, so the CLI asks before it runs, and the API takes an etag that must match the current one.

Shell
sylphx network egress-identities delete orgs/acme/projects/shop/egress_identities/egress-identity --yes

A PrivateLink is the other direction: a customer network reaching a Service without the public internet. Its spec names what is exposed and who may connect:

FieldTypeWhat it is
servicestringrequiredThe Hosting Service exposed.
regionstringrequiredThe region of the link.
allowed_consumersstring[]requiredThe customer network accounts allowed to connect.
Shell
sylphx network private-links create \
  --parent orgs/acme/projects/shop/envs/production \
  --spec.service … \
  --spec.region …

status.state is the lifecycle: pending, established or rejected. When it is established, status.endpoint_service is the endpoint the consumer connects its network to — that is what you send them. An established link keeps carrying traffic while the control plane is impaired; only changes wait.

A link lives under an environment, so it is created, changed and deleted like any other resource in one: allowed_consumers is the field you change as a partner's accounts change, and Delete is destructive.