Shares this environment's internal services with other environments over a private link.
This blueprint is opinionated. It attaches a private link (Private Service Connect on GCP, PrivateLink on AWS) to the internal load balancer in front of Ryvn's managed internal gateway, and the gateway routes each request to a service by hostname. Connected environments call a service at the same internal URL it has here, like https://<name>.<publisherDomain>, and traffic stays on the cloud's private network.
gcpAllowedProjects, or other accounts in awsAllowedPrincipals. On AWS, list other regions in awsAllowedConsumerRegions.publisherId and publisherDomain outputs.To add an environment later, allow it here before you install Private Service Consumer there.
A service is reachable over the link once it has an internal Route. Server installations get one for each port automatically. For other installations, like Helm charts, add a Route with internal exposure and a name under this environment's internal domain. Each installation lists its URLs under Settings > Networking.
This blueprint accepts 4 configurable inputs to customize the installation for your environment.
gcpAllowedProjectsarrayGCP project IDs allowed to connect. Leave empty to allow only this environment's project. If you set it, list this project too when environments in it connect.
awsAllowedPrincipalsarrayAWS principals allowed to connect, such as `arn:aws:iam::123456789012:root` for a whole account. Leave empty to allow only this environment's account. If you set it, list this account too when environments in it connect.
awsAllowedConsumerRegionsarrayOther AWS regions that connecting environments may be in. This environment's own region is always allowed.
gcpNatSubnetCidrstringIPv4 range that incoming connections come from. Must not overlap anything in or routed to this network. Can't be changed after install.
This blueprint exposes 2 outputs that other services can reference.
publisherIdstringSet as `publisherId` on Private Service Consumer.
publisherDomainstringSet as `publisherDomain` on Private Service Consumer.