You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
| Workers Platform Admin | Grants edit and read access to all products typically used as part of Cloudflare's Developer Platform, including [Workers](/workers/), [Pages](/pages/), [Durable Objects](/durable-objects/), [KV](/kv/), [R2](/r2/), Zones, [Zone Analytics](/analytics/account-and-zone-analytics/zone-analytics/) and [Page Rules](/rules/). Cloudflare may add additional read-only permissions to this role as new products are introduced. |
79
79
| Workers Platform (Read-only) | Grants read-only access to all products typically used as part of Cloudflare's Developer Platform, including [Workers](/workers/), [Pages](/pages/), [Durable Objects](/durable-objects/), [KV](/kv/), [R2](/r2/), Zones, [Zone Analytics](/analytics/account-and-zone-analytics/zone-analytics/) and [Page Rules](/rules/). Cloudflare may add additional read-only permissions to this role as new products are introduced. |
80
+
| Connectivity Directory Read | Can view [Workers VPC Services](/workers-vpc/) and [Cloudflare Tunnels](/workers-vpc/configuration/tunnel/).
81
+
| Connectivity Directory Bind | Can read, list, and bind to [Workers VPC Services](/workers-vpc/), as well as read and list [Cloudflare Tunnels](/workers-vpc/configuration/tunnel/).
82
+
| Connectivity Directory Admin | Can view, edit, create, and delete [Workers VPC Services](/workers-vpc/), including the ability to create VPC Services that bind to [Cloudflare Tunnel](/workers-vpc/configuration/tunnel/).
80
83
| Zaraz Admin | Can edit and publish [Zaraz](/zaraz/) configuration. |
81
84
| Zaraz Edit | Can edit [Zaraz](/zaraz/) configuration. |
82
85
| Zaraz Read | Can read [Zaraz](/zaraz/) configuration. |
Copy file name to clipboardExpand all lines: src/content/docs/workers-vpc/configuration/tunnel/index.mdx
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,9 @@ import { GlossaryTooltip, Tabs, TabItem, Example } from "~/components";
9
9
10
10
Cloudflare Tunnel creates secure connections from your infrastructure to Cloudflare's global network, providing the network connectivity that allows Workers to access your private resources.
11
11
12
-
When you create a VPC Service, you specify a tunnel ID and target service. Workers VPC then routes requests from your Worker to the appropriate tunnel, forwards traffic to your private network, connects to the specified hostname or IP address, and returns responses back to your Worker.
12
+
When you create a VPC Service, you specify a tunnel ID and target service. Workers VPC then routes requests from your Worker to the specified tunnel, which establishes a connection to the specified hostname or IP address, such that the target service receives the request and returns a response back to your Worker.
13
+
14
+
To allow members to create VPC Services that represent a target service reachable via a tunnel, you must assign them the **Connectivity Directory Admin** role. Members must possess **Connectivity Directory Bind** role to bind to existing VPC Services from worker.
13
15
14
16
The tunnel maintains persistent connections to Cloudflare, eliminating the need for inbound firewall rules or public IP addresses.
Copy file name to clipboardExpand all lines: src/content/docs/workers-vpc/configuration/vpc-services.mdx
+23-10Lines changed: 23 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -20,6 +20,8 @@ You can use bindings to connect to VPC Services from Workers. Every request made
20
20
21
21
VPC Services enforce that requests are routed to their intended service without exposing the entire network, securing your workloads and preventing server-side request forgery (SSRF).
22
22
23
+
Members must possess **Connectivity Directory Bind** role to bind to existing VPC Services from Workers. Creating VPC Services requires members to possess the **Connectivity Directory Admin** role.
24
+
23
25
:::note
24
26
25
27
Workers VPC is currently in beta. Features and APIs may change before general availability. While in beta, Workers VPC is available for free to all Workers plans.
@@ -34,13 +36,24 @@ A VPC Service consists of:
34
36
-**Tunnel ID**: The Cloudflare Tunnel that provides network connectivity
35
37
-**Hostname or IPv4/IPv6 addresses**: The hostname, or IPv4 and/or IPv6 addresses to use to route to your service from the tunnel in your private network
36
38
-**Ports**: HTTP and/or HTTPS port configuration (optional, defaults to 80/443)
39
+
-**Resolver IPs**: Optionally, a specific resolver IP can be provided -- when not provided, `cloudflared` will direct DNS traffic to the currently configured default system resolver.
40
+
41
+
Requests are encrypted in flight until they reach your network via a tunnel, regardless of the scheme used in the URL provided to `fetch`. If the `http` scheme is used, a plaintext connection is established to the service from the tunnel.
42
+
43
+
The `https` scheme can be used for an encrypted connection within your network, between the tunnel and your service. When the `https` scheme is specified, a hostname provided to the `fetch()` operation is utilized as the Server Name Indication (SNI) value.
44
+
45
+
VPC Services default to allowing both `http` and `https` schemes to be used. You can provide values for only one of `http_port` or `https_port` to enforce the use of a particular scheme.
46
+
47
+
When Workers VPC is unable to establish a connection to your service, `fetch()` will throw an exception.
37
48
38
49
:::note
39
-
The [VPC Service configurations](/workers-vpc/configuration/vpc-services/#vpc-service-configuration) will always be used to connect and route requests to your services in external networks, even if a different URL or host is present in the actual `fetch()` operation of the Worker code.
40
50
41
-
The host provided in the `fetch()` operation is not used to route requests, and instead only populates the `Host` field for a HTTP request that can be parsed by the server and used for Server Name Indication (SNI), when the `https` scheme is specified.
51
+
The [VPC Service configuration](/workers-vpc/configuration/vpc-services/#vpc-service-configuration) host and port(s) will always be used to connect and route requests to your services, even if a different host or port is present in the URL provided to the `fetch()` operation in the Worker code.
52
+
53
+
The host provided in the `fetch()` operation is not used to route requests, and instead only populates the `Host` field for a HTTP request, or `Host` and the Server Name Indication (SNI) value presented to your service for a HTTPS request.
54
+
55
+
The port provided in the `fetch()` operation is ignored — the port specified in the VPC Service configuration for the provided scheme will be used.
42
56
43
-
The port provided in the `fetch()` operation is ignored — the port specified in the VPC Service configuration will be used.
44
57
:::
45
58
46
59
## Configuration example
@@ -83,7 +96,7 @@ The following is an example of a VPC Service for a service using custom HTTP and
remote = true# When true, utilizes [remote bindings](/workers/development-testing/#remote-bindings) to allow access to the VPC Service during local development.
0 commit comments