Application network access
Use this route to define which IP addresses can reach a public HTTP application. The configuration fully replaces the current lists.
Authentication and permissions
Accepts an organization API Key (x-api-key: znf_... or Authorization: Bearer znf_...) or a user token with x-organization-id. Requires project.network.update on project:<project-id>; owner has full access.
Project requirements:
- be an HTTP application;
- have public exposure (see Project information);
- be on a plan with
capabilities.network_access: truein theGET /v1/project/planscatalog.
Limit: 10 requests per minute.
Update the lists
PATCH /v1/project/:id/network-access| Field | Type | Required | Description |
|---|---|---|---|
network_access.ingress_white_list | array | Yes | Allowed ranges, up to 10 items |
network_access.ingress_black_list | array | Yes | Blocked ranges, up to 10 items; use [] for none |
*.cidr | string | Yes | IPv4 range in CIDR notation, such as 203.0.113.0/24 or 198.51.100.7/32 |
*.description | string | Yes | Rule label, from 1 to 256 characters |
{
"network_access": {
"ingress_white_list": [
{ "cidr": "203.0.113.0/24", "description": "Office" },
{ "cidr": "198.51.100.7/32", "description": "CI server" }
],
"ingress_black_list": []
}
}{
"status": "success",
"message": "updated the network access with success"
}How rules are evaluated
ingress_white_listdefines who can access: only the listed IPs and ranges get in. To keep the application open to everyone, use0.0.0.0/0.ingress_black_listblocks specific IPs and ranges, even when they are inside an allowed range, such as0.0.0.0/0.- With an empty
ingress_white_list, no address is allowed.
Only IPv4 is accepted. See usage examples in Network access.
Errors
| Code | Situation |
|---|---|
400 | Invalid body: missing list, more than 10 items, malformed CIDR, or empty description |
401 | Project that is not HTTP (cant change database config) or plan without the feature (dont have permission to block ip) |
404 | Project not found |
409 | Project with private exposure (project is not publicly exposed) |
429 | Rate limit exceeded |
500 | Failure applying the rules; try again |
Example
curl -X PATCH "https://api.zenifra.com/v1/project/6650f1a2b3c4d5e6f7a8b9c0/network-access" \
-H "x-api-key: znf_..." \
-H "Content-Type: application/json" \
-d '{"network_access": {"ingress_white_list": [{"cidr": "0.0.0.0/0", "description": "Public access"}], "ingress_black_list": []}}'Next steps
- Set the rules at creation with
config.network_accessin Create, list, and delete projects. - Configure the application's domain and subdomain.
- Review security practices.
Last updated on