←Marketplace

Private Service Publisher

Description

Shares this environment's internal services with other environments over a private link.

This blueprint is opinionated. It attaches a private link (Private Service Connect on GCP, PrivateLink on AWS) to the internal load balancer in front of Ryvn's managed internal gateway, and the gateway routes each request to a service by hostname. Connected environments call a service at the same internal URL it has here, like https://<name>.<publisherDomain>, and traffic stays on the cloud's private network.

Setup

  1. Install this blueprint once, on the environment that runs the services.
  2. Allow the environments that will connect. They must be on the same cloud as this environment, and on GCP in the same region. Environments in this GCP project or AWS account are allowed by default. List other projects in gcpAllowedProjects, or other accounts in awsAllowedPrincipals. On AWS, list other regions in awsAllowedConsumerRegions.
  3. Install Private Service Consumer on each connecting environment with this installation's publisherId and publisherDomain outputs.

To add an environment later, allow it here before you install Private Service Consumer there.

Publish a service

A service is reachable over the link once it has an internal Route. Server installations get one for each port automatically. For other installations, like Helm charts, add a Route with internal exposure and a name under this environment's internal domain. Each installation lists its URLs under Settings > Networking.

What to expect

  • The link carries HTTP, including gRPC. It doesn't carry other protocols, like direct database connections.
  • Every internal Route here is reachable from every connected environment.
  • Requests arrive from the link's addresses, so services can't tell callers apart by IP. Use authentication to control who can call a service.
  • To disconnect an environment, uninstall Private Service Consumer there, then remove it from the allowed lists. On AWS, removing it from the lists alone doesn't disconnect it.
  • Uninstall Private Service Consumer everywhere before you uninstall this blueprint or delete this environment.

Configuration Inputs

This blueprint accepts 4 configurable inputs to customize the installation for your environment.

gcpAllowedProjectsarray

GCP project IDs allowed to connect. Leave empty to allow only this environment's project. If you set it, list this project too when environments in it connect.

awsAllowedPrincipalsarray

AWS principals allowed to connect, such as `arn:aws:iam::123456789012:root` for a whole account. Leave empty to allow only this environment's account. If you set it, list this account too when environments in it connect.

awsAllowedConsumerRegionsarray

Other AWS regions that connecting environments may be in. This environment's own region is always allowed.

gcpNatSubnetCidrstring

IPv4 range that incoming connections come from. Must not overlap anything in or routed to this network. Can't be changed after install.

Outputs

This blueprint exposes 2 outputs that other services can reference.

publisherIdstring

Set as `publisherId` on Private Service Consumer.

publisherDomainstring

Set as `publisherDomain` on Private Service Consumer.