Cloudflare - v1.3.0
    Preparing search index...

    Class VpcNetworkBinding<E>

    Accessor for a VPC Network binding.

    The broad half of Workers VPC. Where VpcServiceBinding is pinned to one private host and port at deploy time, this opens a whole network — a Cloudflare Tunnel by tunnel_id, or Cloudflare Mesh by network_id — and lets each call name its destination. Nothing has to be registered in advance, which is what makes it usable for a private network whose addresses are not known when the Worker ships.

    That reach is also the reason to prefer a VPC Service when one will do. A Worker holding this binding can reach anything on the network, so a request that influences the address it calls is a server-side request forgery with a private network behind it. Cloudflare's own answer to constraining that is a VPC Service per destination, not a filter — and see VpcNetworkSettings for why this package does not offer one.

    fetch for HTTP, connect for everything that is not: Redis, Memcached, MQTT, anything speaking its own bytes. connect is plaintext TCP at the time of writing, so a private service expecting TLS needs it terminated on the private side.

    Unique here, and not by preference. @cloudflare/workers-types declares nothing for Workers VPC at the pinned version, and unlike a VPC Service — which is Fetcher structurally — a network binding's connect has no existing type to borrow. VpcNetwork is therefore written here, kept to the two documented methods, and meant to be deleted when the real type ships. See that interface for what it costs.

    const network = new VpcNetworkBinding()

    const response = await network.fetch(env, 'http://10.0.1.50:8080/api/data')
    const socket = await network.connect(env, '10.0.1.50:6379')

    Bayu Dwiyan Satria

    1.0.0

    1.3.0

    Type Parameters

    Hierarchy (View Summary)

    Index
    • get name(): string

      The binding name this instance resolves.

      Returns string

      The binding name as declared in wrangler.json.

    • Opens a TCP socket to a destination on the private network.

      Parameters

      • env: E

        The Worker environment.

      • address: string | SocketAddress

        The private destination, as host:port or a SocketAddress.

      Returns Promise<Socket>

      The connected socket.

      The caller owns the socket from here — closing it, and draining both sides. Nothing in this package wraps that, because a socket's lifetime belongs to the protocol being spoken over it and this class knows no protocol.

      MissingBindingError When the VPC Network binding is absent.

    • Sends a request to a destination on the private network.

      Parameters

      • env: E

        The Worker environment.

      • resource: string | URL | Request<unknown, CfProperties<unknown>>

        The private destination, as a URL, string, or Request.

      • Optionaloptions: RequestInit

        Standard request options.

      Returns Promise<Response>

      The response from the private service.

      The URL decides the destination, so it is the argument that must never come from a request this Worker is serving. Any hostname or address reachable through the bound tunnel or mesh is in range.

      MissingBindingError When the VPC Network binding is absent.

    • Checks whether the binding is available on the given environment.

      Use this to degrade gracefully when a binding is optional.

      Parameters

      • env: E

        The Worker environment.

      Returns boolean

      true when the binding is present.