Outbound CLI and API

Inspect the profile. Verify the route.

The development CLI can list egress profiles. The API defines creation, enable and disable operations. Here is the current boundary between those tools and a working exit.

PROFILE RECORD ≠ WORKING ROUTE

DEVELOPMENT CLI / INSPECTfibmesh egress list
--format text
CLI
List profiles
API
Create · enable · disable
Verification
Apply policy → test the destination

Command-line access

Listing exists. Full CLI management is not implemented.

The implemented command is fibmesh egress list, with text or JSON output. Creation, enable and disable commands are not implemented in the checked CLI. Its login command is also a pending implementation.

These are development tools and contract references. They are not a production installation or authenticated signup guide. The development CLI defaults to a local API; use an explicitly authorised environment.

fibmesh egress list --format text
fibmesh egress list --format json

The command requests GET /v1/egress-profiles. It reports administrative records; it does not perform a tunnel or source-address test. Use fibmesh status and fibmesh diagnostics for local identity and cached-policy information, with the same distinction between recorded state and live delivery.

API contract

Four operations, with different effects.

Swipe the table sideways to see all columns.

Operation Contract endpoint Result to expect
List profiles GET /v1/egress-profiles Profile records for the authorised organisation.
Create a profile POST /v1/egress-profiles A new, initially disabled profile record; HTTP 201.
Enable a profile POST /v1/egress-profiles/{id}/enable An accepted state change; HTTP 202. Other profiles in the organisation are disabled.
Disable a profile POST /v1/egress-profiles/{id}/disable An accepted state change; HTTP 202. Verify native route restoration separately.

These are authenticated user operations in the contract. A service-account or machine-token flow for unattended automation is not established by these endpoints. Confirm public API access, authentication and permissions for the supported deployment.

Creation does not provision an exit gateway or prove address allocation. The returned gateway_node_id and assigned_public_ip can be empty. An active or enabled record is administrative state, not evidence that internet traffic reaches a destination.

Names in the contract

Match the requested mode to the agreed service.

The create request requires name and mode; region is optional. It does not accept an application selector, destination list or per-device exit binding.

Swipe the table sideways to see all columns.

API mode Product intent What still needs confirmation
secure_internet Internet routing through a Fibmesh exit Supported platform, assigned exit and actual traffic behaviour.
regular_vpn Regular exit routing No fixed or exclusive source address is implied.
stable_ip A recognised outgoing source Assigned address, continuity and retention terms.
dedicated_ip Exclusive outgoing identity Confirmed allocation, exclusivity and commercial scope.

The mode names are API identifiers, not separate public products. The current policy builder requests full-tunnel routing for these profiles, including both default address-family routes. That does not certify working IPv6 delivery or eliminate operating-system exceptions.

Enabling a profile currently selects the active exit for the organisation. Do not describe these operations as per-user region switching or simultaneous per-device exits.

From a record to a connection

Check every stage before reporting success.

  1. Read before writing

    List the current profiles and identify the organisation, active profile and intended change. Avoid replacing another team’s exit unexpectedly.

  2. Reconcile the response

    Record the returned ID. If a create call times out, inspect existing records before retrying: these operations do not establish an idempotency-key contract.

  3. Observe applied policy

    Confirm assigned delivery and the affected endpoint’s new policy and execution result. Use a bounded wait; never poll indefinitely for an assumed success state.

  4. Test the real destination

    Verify the source, application response, DNS and IP-family behaviour. Then exercise the agreed disable and recovery procedure.

The checked API does not expose a complete profile edit or deletion lifecycle. Disabling is not a substitute for deleting an account resource or releasing a public-address reservation. Agree the supported operator procedure for retirement.

Keep endpoint private keys local and redact secrets from logs. Do not use database credentials or service-role keys in a customer CLI or browser.

Use the deployment verification guide →