01 / Connection design
Four jobs. Four different network decisions.
A public preview, a private database and a provider allowlist should not share the same exposure settings.
Reach the build server
Enroll the server and developer devices. Give the engineering access group a private path. Keep the build system’s own authentication.
Networks →Share port 3000
In the Publish design, expose a selected HTTP app through a supported connector. A reviewer opens a managed hostname; your database and SSH service remain separate.
Publish →Pass a source-IP check
Assess a stable source with full-tunnel Outbound, or Public IPs for selected destinations. Incoming access is a separate choice.
Outbound →Expose a selected protocol
Assess a device or gateway public address when an HTTP hostname is not enough. Start with explicit firewall rules and a return-path check.
Public IPs →02 / Worked example
A preview for your reviewer. A database for your team.
Two applications on the same server can have different reachability. The resource is shared; the permission is not.
Publish is available with assisted setup. This guide explains the workflow; confirm supported software and the setup procedure with Fibmesh.
One application
Client review preview
- External reviewer
- HTTPS gateway
- 127.0.0.1:3000
- Target
- Studio server
- Local address
- 127.0.0.1
- Application port
- 3000 · HTTP
- Hostname
- Fibmesh-managed subdomain
Database on port 5432: no publishing rule.
The application boundary
Your web application listens on 127.0.0.1:3000 on the connector’s own host. A Publish link describes that target address and port, using a Fibmesh-managed subdomain and the supported HTTP publication path. Test the hostname as an external reviewer.
The database boundary
PostgreSQL listens on port 5432. Creating the web preview does not publish that port. Give approved developers a private resource path instead, and require the database’s own credentials and roles.
The end of the review
Remove the Publish link when review ends. Inspect the resulting state and confirm the old public path no longer serves the application. Keep private engineering access only for members who still need it.
03 / Resource model
One resource identity. Explicit capabilities.
Start with the enrolled device or server. Private access, application publication, public addressing and internet routing are separate choices.
Enroll in the correct workspace
The endpoint creates its keypair locally. Enrollment establishes a distinct resource identity; the backend receives the public key by default.
A private key is not a browser-side configuration field.Choose the capability
Private membership, application publication, public identity and outgoing routing are different requests. An access group is not a prerequisite for every product.
Inspect the policy and its result
The backend decides the intended network plan. A supported native executor validates and applies the authorised changes, then reports its result.
Check Latest Sync: when the resource last exchanged policy and reported what it applied.Change or retire the resource
Remove obsolete publication, membership or allocation deliberately. Check observed delivery and clean up the application-side permission as well.
04 / State, not guesswork
Accepted is not the same as applied.
An API or dashboard can accept a request before a gateway, provider or endpoint has finished applying it.
Read the two generations
Desired state records the approved plan. Observed state records the generation that the executor has reported. If desired generation is 12 and observed generation is 11, the latest change still needs confirmation.
For a public-IP assignment, provisioning, active, degraded, paused and released describe different lifecycle states. A successful request alone is not evidence that traffic has reached the intended target.
Follow policy delivery →Illustrative state · not an API response
resource: build-server
capability: public-ip
desired_generation: 12
observed_generation: 11
status: provisioning
Next check:
executor result + assigned location
firewall rules + destination listener05 / Reading paths
Go straight to the decision you are making.
Design the path
Understand private membership, incoming publication and outgoing identity before changing routes.
Private and public access →Inbound or outbound →
Choose the runtime
Match the resource to a supported native endpoint, gateway or separately assessed Compatibility Mode profile.
Connection methods →Deployment options →
Understand the controls
Check firewall scope, key ownership and the difference between a private resource name and public DNS.
Managed firewall →Security architecture →
Automation
Know which controls you can use.
Command names in the repository do not establish a supported public package or external authentication flow. Use the product guides to distinguish implemented operations from proposed interfaces.
| Product | Repository and design scope | Read |
|---|---|---|
| Networks | Device/gateway enrollment, policy inspection and diagnostic operations exist; availability depends on the supported release and credentials | Networks CLI & API |
| Publish | Legacy ingress-rule commands exist, but they do not establish the Publish lifecycle, HTTPS or custom-domain support | Publish CLI design |
| Public IPs | API contracts cover assignments; a dedicated Public IP CLI command group is proposed, not implemented | Public IPs CLI & API |
| Outbound | Egress profile listing exists in the CLI; profile mutations belong to the API contract, not a complete CLI lifecycle | Outbound CLI & API |
Public SDKs and a supported external authentication flow have not been released. Never put endpoint private keys or backend database credentials into scripts, browser code or support reports.
06 / Inspect the contract
A request describes the target and the traffic scope.
/v1/public-ip/assignmentsInternal contract referenceRequest a resource, not a tunnel.
The create operation uses the interactive user principal class and requires an Idempotency-Key header of 8–255 characters. Endpoint and gateway runtime credentials are separate.
The contract returns 201 for creation. Pause, resume and release operations return 202 after committing desired state. Neither establishes that the provider or executor has converged.
The example starts with managed firewall mode and no inbound rules. It is a blocked inbound starting state, not a deployed public service.
PublicIPAssignmentRequest
required:
target_type, target_id, capability,
routing_mode, firewall_mode
target_type: device | gateway
routing_mode:
public_reachability
selected_outbound
full_internet_routing
firewall_mode: managed | fully_openInspect an illustrative request body
{
"target_type": "device",
"target_id": "example-device-id",
"capability": "ipv6_public_identity",
"ip_version": "ipv6",
"routing_mode": "public_reachability",
"firewall_mode": "managed",
"firewall_rules": []
}example-device-id is a placeholder, not an enrolled resource.
Source: repository OpenAPI / PublicIPAssignmentRequest. Read-only design reference. External API access, supported authentication and public SDKs are not released by this example.
07 / Integration boundary
What these references support today.
The developer pages explain the platform and repository contracts. The internal OpenAPI model distinguishes interactive user, enrollment, endpoint-runtime and gateway-runtime credentials; those credential classes cannot be substituted for each other. Generated internal TypeScript and C# clients are repository tools, not a released public SDK.
External authentication, API versioning, scopes, examples and support terms must be released together before a customer builds an operational integration. Check product, platform and market availability for an evaluation. This page does not ask you to run an unverified installer or send credentials to a sample endpoint.
