Network and access control
This page explains how an HTTP project receives traffic and how to limit who can reach it. To point your own domain, see Custom domains.
Exposure: public or private
Every HTTP project is created with an exposure:
| Exposure | Behavior | Best for |
|---|---|---|
| Public | Gets a public HTTPS route, a *.clients.zenifra.com address, and accepts custom domains | Websites, APIs, dashboards, and webhooks |
| Private | Runs without a public internet route and gets no domain | Workers, queues, scheduled routines, and automations |
A private project can still reach the internet and your databases and managed services. It just does not receive external requests.
Zenifra subdomain
Public projects automatically get a *.clients.zenifra.com subdomain with HTTPS. The platform uses the project name; if it is already taken, it appends a random sequence to keep the address unique.
On plans above Basic, you can choose a custom subdomain with 6 to 54 characters, using lowercase letters, numbers, and inner hyphens.
IP access control
On plans that include the feature, public projects can restrict access by IP address. The console shows the option during creation and in Edit project when the plan allows it.
Whitelist (allow list)
When the whitelist has entries, only the listed IPs or ranges reach the project. Everything else is blocked.
Blacklist (block list)
The blacklist blocks specific IPs or ranges, even if they also appear in the whitelist.
Format
Entries use CIDR notation, with a description to identify the rule:
| Entry | Meaning |
|---|---|
203.0.113.10/32 | A single IP |
203.0.113.0/24 | The 256-address range from 203.0.113.0 to 203.0.113.255 |
0.0.0.0/0 | Any IPv4 address |
In the console, the Add current IP button adds your address automatically.
Limits and behavior
- Up to 10 entries in the whitelist and up to 10 entries in the blacklist.
- Changing the lists does not restart the instances.
- Available only for public HTTP projects; private projects already receive no external traffic.
- The change requires the project's network update permission and a plan with the feature. Without it, the API rejects the change.
Use cases
- Admin dashboard: whitelist with your office and company VPN IPs.
- Business-to-business API: whitelist with the partner's outbound IPs.
- Staging: whitelist with the team's IPs while the application is not launched.
- Occasional abuse: blacklist with an IP or range generating unwanted traffic.
IP control complements, but does not replace, authentication in your application. Keep login, tokens, or API keys on sensitive routes.
Next steps
FAQ
Can I switch a project from private to public?
Exposure is available in Edit project. The change affects routes and domains, so the console asks for confirmation before applying it.
How do I know whether my plan includes IP control?
The console shows each plan's features during creation and only displays the IP lists when the plan allows it. In the CLI, zenifra plans --type http describes the available capabilities.
My own whitelist locked me out. What now?
The console remains reachable as usual, because the lists apply only to application traffic. Open Edit project, add your current IP, and save.
Persistent storage
Learn when to use persistent storage in Zenifra HTTP projects, how to choose capacity and directory, and what can change after creation.
Custom domains
Configure apex domains, subdomains, CNAME records, TXT validation records, and HTTPS to point your own domain to an application hosted on Zenifra.