Application network access

Use this route to define which IP addresses can reach a public HTTP application. The configuration fully replaces the current lists.

Authentication and permissions

Accepts an organization API Key (x-api-key: znf_... or Authorization: Bearer znf_...) or a user token with x-organization-id. Requires project.network.update on project:<project-id>; owner has full access.

Project requirements:

  • be an HTTP application;
  • have public exposure (see Project information);
  • be on a plan with capabilities.network_access: true in the GET /v1/project/plans catalog.

Limit: 10 requests per minute.

Update the lists

PATCH /v1/project/:id/network-access
FieldTypeRequiredDescription
network_access.ingress_white_listarrayYesAllowed ranges, up to 10 items
network_access.ingress_black_listarrayYesBlocked ranges, up to 10 items; use [] for none
*.cidrstringYesIPv4 range in CIDR notation, such as 203.0.113.0/24 or 198.51.100.7/32
*.descriptionstringYesRule label, from 1 to 256 characters
{
  "network_access": {
    "ingress_white_list": [
      { "cidr": "203.0.113.0/24", "description": "Office" },
      { "cidr": "198.51.100.7/32", "description": "CI server" }
    ],
    "ingress_black_list": []
  }
}
{
  "status": "success",
  "message": "updated the network access with success"
}

How rules are evaluated

  • ingress_white_list defines who can access: only the listed IPs and ranges get in. To keep the application open to everyone, use 0.0.0.0/0.
  • ingress_black_list blocks specific IPs and ranges, even when they are inside an allowed range, such as 0.0.0.0/0.
  • With an empty ingress_white_list, no address is allowed.

Only IPv4 is accepted. See usage examples in Network access.

Errors

CodeSituation
400Invalid body: missing list, more than 10 items, malformed CIDR, or empty description
401Project that is not HTTP (cant change database config) or plan without the feature (dont have permission to block ip)
404Project not found
409Project with private exposure (project is not publicly exposed)
429Rate limit exceeded
500Failure applying the rules; try again

Example

curl -X PATCH "https://api.zenifra.com/v1/project/6650f1a2b3c4d5e6f7a8b9c0/network-access" \
  -H "x-api-key: znf_..." \
  -H "Content-Type: application/json" \
  -d '{"network_access": {"ingress_white_list": [{"cidr": "0.0.0.0/0", "description": "Public access"}], "ingress_black_list": []}}'

Next steps

Last updated on

On this page