Developers

Build the app. Choose how it gets reached.

Keep your database private, share an HTTP preview, or give a build job a known outgoing address. Start with the connection your application needs, then follow its identity, policy and runtime.

connection-planIllustrative connection plan
Device / Serverstudio-serverOne identity. Separate paths.
:3000 · HTTPPublish link → Reviewer
:5432 · DatabaseNetworks → Engineering
Provider APIChosen source → Provider

Application logins and data permissions remain in your application.

01 / Connection design

Four jobs. Four different network decisions.

A public preview, a private database and a provider allowlist should not share the same exposure settings.

Internal development

Reach the build server

Enroll the server and developer devices. Give the engineering access group a private path. Keep the build system’s own authentication.

Networks →
Application review

Share port 3000

In the Publish design, expose a selected HTTP app through a supported connector. A reviewer opens a managed hostname; your database and SSH service remain separate.

Publish →
Third-party integration

Pass a source-IP check

Assess a stable source with full-tunnel Outbound, or Public IPs for selected destinations. Incoming access is a separate choice.

Outbound →
Address-based service

Expose a selected protocol

Assess a device or gateway public address when an HTTP hostname is not enough. Start with explicit firewall rules and a return-path check.

Public IPs →

02 / Worked example

A preview for your reviewer. A database for your team.

Two applications on the same server can have different reachability. The resource is shared; the permission is not.

Publish is available with assisted setup. This guide explains the workflow; confirm supported software and the setup procedure with Fibmesh.

fibmeshPublishIllustrative product model

One application

Client review preview

  1. External reviewer
  2. HTTPS gateway
  3. 127.0.0.1:3000
Target
Studio server
Local address
127.0.0.1
Application port
3000 · HTTP
Hostname
Fibmesh-managed subdomain

Database on port 5432: no publishing rule.

Example configuration, not a connected account or release confirmation.

The application boundary

Your web application listens on 127.0.0.1:3000 on the connector’s own host. A Publish link describes that target address and port, using a Fibmesh-managed subdomain and the supported HTTP publication path. Test the hostname as an external reviewer.

The database boundary

PostgreSQL listens on port 5432. Creating the web preview does not publish that port. Give approved developers a private resource path instead, and require the database’s own credentials and roles.

The end of the review

Remove the Publish link when review ends. Inspect the resulting state and confirm the old public path no longer serves the application. Keep private engineering access only for members who still need it.

Read the application publishing scenario →

03 / Resource model

One resource identity. Explicit capabilities.

Start with the enrolled device or server. Private access, application publication, public addressing and internet routing are separate choices.

  1. Enroll in the correct workspace

    The endpoint creates its keypair locally. Enrollment establishes a distinct resource identity; the backend receives the public key by default.

    A private key is not a browser-side configuration field.
  2. Choose the capability

    Private membership, application publication, public identity and outgoing routing are different requests. An access group is not a prerequisite for every product.

  3. Inspect the policy and its result

    The backend decides the intended network plan. A supported native executor validates and applies the authorised changes, then reports its result.

    Check Latest Sync: when the resource last exchanged policy and reported what it applied.
  4. Change or retire the resource

    Remove obsolete publication, membership or allocation deliberately. Check observed delivery and clean up the application-side permission as well.

04 / State, not guesswork

Accepted is not the same as applied.

An API or dashboard can accept a request before a gateway, provider or endpoint has finished applying it.

Read the two generations

Desired state records the approved plan. Observed state records the generation that the executor has reported. If desired generation is 12 and observed generation is 11, the latest change still needs confirmation.

For a public-IP assignment, provisioning, active, degraded, paused and released describe different lifecycle states. A successful request alone is not evidence that traffic has reached the intended target.

Follow policy delivery →

Illustrative state · not an API response

resource: build-server
capability: public-ip
desired_generation: 12
observed_generation: 11
status: provisioning

Next check:
  executor result + assigned location
  firewall rules + destination listener

05 / Reading paths

Go straight to the decision you are making.

Design the path

Understand private membership, incoming publication and outgoing identity before changing routes.

Private and public access →
Inbound or outbound →

Choose the runtime

Match the resource to a supported native endpoint, gateway or separately assessed Compatibility Mode profile.

Connection methods →
Deployment options →

Understand the controls

Check firewall scope, key ownership and the difference between a private resource name and public DNS.

Managed firewall →
Security architecture →

Automation

Know which controls you can use.

Command names in the repository do not establish a supported public package or external authentication flow. Use the product guides to distinguish implemented operations from proposed interfaces.

Product Repository and design scope Read
Networks Device/gateway enrollment, policy inspection and diagnostic operations exist; availability depends on the supported release and credentials Networks CLI & API
Publish Legacy ingress-rule commands exist, but they do not establish the Publish lifecycle, HTTPS or custom-domain support Publish CLI design
Public IPs API contracts cover assignments; a dedicated Public IP CLI command group is proposed, not implemented Public IPs CLI & API
Outbound Egress profile listing exists in the CLI; profile mutations belong to the API contract, not a complete CLI lifecycle Outbound CLI & API

Public SDKs and a supported external authentication flow have not been released. Never put endpoint private keys or backend database credentials into scripts, browser code or support reports.

06 / Inspect the contract

A request describes the target and the traffic scope.

POST/v1/public-ip/assignmentsInternal contract reference

Request a resource, not a tunnel.

The create operation uses the interactive user principal class and requires an Idempotency-Key header of 8–255 characters. Endpoint and gateway runtime credentials are separate.

The contract returns 201 for creation. Pause, resume and release operations return 202 after committing desired state. Neither establishes that the provider or executor has converged.

The example starts with managed firewall mode and no inbound rules. It is a blocked inbound starting state, not a deployed public service.

PublicIPAssignmentRequest
required:
  target_type, target_id, capability,
  routing_mode, firewall_mode

target_type: device | gateway
routing_mode:
  public_reachability
  selected_outbound
  full_internet_routing
firewall_mode: managed | fully_open
Inspect an illustrative request body
{
  "target_type": "device",
  "target_id": "example-device-id",
  "capability": "ipv6_public_identity",
  "ip_version": "ipv6",
  "routing_mode": "public_reachability",
  "firewall_mode": "managed",
  "firewall_rules": []
}

example-device-id is a placeholder, not an enrolled resource.

Source: repository OpenAPI / PublicIPAssignmentRequest. Read-only design reference. External API access, supported authentication and public SDKs are not released by this example.

07 / Integration boundary

What these references support today.

The developer pages explain the platform and repository contracts. The internal OpenAPI model distinguishes interactive user, enrollment, endpoint-runtime and gateway-runtime credentials; those credential classes cannot be substituted for each other. Generated internal TypeScript and C# clients are repository tools, not a released public SDK.

External authentication, API versioning, scopes, examples and support terms must be released together before a customer builds an operational integration. Check product, platform and market availability for an evaluation. This page does not ask you to run an unverified installer or send credentials to a sample endpoint.