Cloudflare - v1.3.0
    Preparing search index...

    Class VpcServiceBinding<E>

    Accessor for a VPC Service binding.

    Reaches one service on a private network — an internal API, a database's HTTP front, something in an AWS VPC or on a rack — without that service being exposed to the internet. Traffic goes through a Cloudflare Tunnel, so the private side needs no inbound firewall rule at all.

    The destination is fixed in wrangler.json as a service_id, which is the property worth understanding rather than working around: a Worker holding this binding can reach exactly one private endpoint, and no request it handles can talk it into reaching another. VpcNetworkBinding trades that away deliberately, and the choice between them is a security decision before it is an ergonomic one.

    The binding offers fetch and nothing else, which is Fetcher structurally — the same reasoning that types BrowserBinding. That matters more here than it did there, because @cloudflare/workers-types declares nothing for Workers VPC at the version this package pins. Naming Fetcher means this class describes no shape of its own while the product is in beta.

    VpcNetworkBinding could not manage the same trick, and says so.

    const internal = new VpcServiceBinding()

    const response = await internal.fetch(env, 'https://internal-api.example.com/positions')

    Bayu Dwiyan Satria

    1.0.0

    1.3.0

    Type Parameters

    Hierarchy (View Summary)

    Index
    • get name(): string

      The binding name this instance resolves.

      Returns string

      The binding name as declared in wrangler.json.

    • Sends a request to the bound private service.

      Parameters

      • env: E

        The Worker environment.

      • resource: string | URL | Request<unknown, CfProperties<unknown>>

        The request, as a URL, string, or Request.

      • Optionaloptions: RequestInit

        Standard request options.

      Returns Promise<Response>

      The response from the private service.

      The hostname in the URL is resolved on the private side, so it needs to be the name that side answers to rather than anything public. The binding decides where the request goes regardless; the URL supplies the path, method and body.

      Failures arrive as they would from any fetch — an unreachable tunnel is a rejected promise, not a status code — so a caller that must not fail with the private side should catch here rather than inspect the response.

      MissingBindingError When the VPC Service binding is absent.

    • Checks whether the binding is available on the given environment.

      Use this to degrade gracefully when a binding is optional.

      Parameters

      • env: E

        The Worker environment.

      Returns boolean

      true when the binding is present.

    • Resolves the binding without throwing.

      Parameters

      • env: E

        The Worker environment.

      Returns Fetcher<undefined, never>

      The resolved binding, or null when it is not configured.