Constructs a VpcNetworkBinding instance.
Optionalsettings: VpcNetworkSettings
Resolved settings. Defaults to resolve('vpcNetwork'), so callers
normally construct this with no arguments at all.
The binding name this instance resolves.
The binding name as declared in wrangler.json.
Opens a TCP socket to a destination on the private network.
The Worker environment.
The private destination, as host:port or a SocketAddress.
The connected socket.
The caller owns the socket from here — closing it, and draining both sides. Nothing in this package wraps that, because a socket's lifetime belongs to the protocol being spoken over it and this class knows no protocol.
MissingBindingError When the VPC Network binding is absent.
Sends a request to a destination on the private network.
The Worker environment.
The private destination, as a URL, string, or Request.
Optionaloptions: RequestInit
Standard request options.
The response from the private service.
The URL decides the destination, so it is the argument that must never come from a request this Worker is serving. Any hostname or address reachable through the bound tunnel or mesh is in range.
MissingBindingError When the VPC Network binding is absent.
Checks whether the binding is available on the given environment.
Use this to degrade gracefully when a binding is optional.
The Worker environment.
true when the binding is present.
Resolves the binding, failing fast when it is not configured.
The Worker environment.
The resolved binding.
MissingBindingError When the binding is absent from the environment.
Resolves the binding without throwing.
The Worker environment.
The resolved binding, or null when it is not configured.
Accessor for a VPC Network binding.
Remarks
The broad half of Workers VPC. Where VpcServiceBinding is pinned to one private host and port at deploy time, this opens a whole network — a Cloudflare Tunnel by
tunnel_id, or Cloudflare Mesh bynetwork_id— and lets each call name its destination. Nothing has to be registered in advance, which is what makes it usable for a private network whose addresses are not known when the Worker ships.That reach is also the reason to prefer a VPC Service when one will do. A Worker holding this binding can reach anything on the network, so a request that influences the address it calls is a server-side request forgery with a private network behind it. Cloudflare's own answer to constraining that is a VPC Service per destination, not a filter — and see VpcNetworkSettings for why this package does not offer one.
Two protocols
fetch for HTTP, connect for everything that is not: Redis, Memcached, MQTT, anything speaking its own bytes.
connectis plaintext TCP at the time of writing, so a private service expecting TLS needs it terminated on the private side.This one names a type this package declares
Unique here, and not by preference.
@cloudflare/workers-typesdeclares nothing for Workers VPC at the pinned version, and unlike a VPC Service — which isFetcherstructurally — a network binding'sconnecthas no existing type to borrow. VpcNetwork is therefore written here, kept to the two documented methods, and meant to be deleted when the real type ships. See that interface for what it costs.Example
Author
Bayu Dwiyan Satria
Version
1.0.0
Since
1.3.0