Constructs a VpcServiceBinding instance.
Optionalsettings: VpcServiceSettings
Resolved settings. Defaults to resolve('vpcService'), so callers
normally construct this with no arguments at all.
The binding name this instance resolves.
The binding name as declared in wrangler.json.
Sends a request to the bound private service.
The Worker environment.
The request, as a URL, string, or Request.
Optionaloptions: RequestInit
Standard request options.
The response from the private service.
The hostname in the URL is resolved on the private side, so it needs to be the name that side answers to rather than anything public. The binding decides where the request goes regardless; the URL supplies the path, method and body.
Failures arrive as they would from any fetch — an unreachable tunnel is a
rejected promise, not a status code — so a caller that must not fail with
the private side should catch here rather than inspect the response.
MissingBindingError When the VPC Service binding is absent.
Checks whether the binding is available on the given environment.
Use this to degrade gracefully when a binding is optional.
The Worker environment.
true when the binding is present.
Resolves the binding, failing fast when it is not configured.
The Worker environment.
The resolved binding.
MissingBindingError When the binding is absent from the environment.
Resolves the binding without throwing.
The Worker environment.
The resolved binding, or null when it is not configured.
Accessor for a VPC Service binding.
Remarks
Reaches one service on a private network — an internal API, a database's HTTP front, something in an AWS VPC or on a rack — without that service being exposed to the internet. Traffic goes through a Cloudflare Tunnel, so the private side needs no inbound firewall rule at all.
The destination is fixed in
wrangler.jsonas aservice_id, which is the property worth understanding rather than working around: a Worker holding this binding can reach exactly one private endpoint, and no request it handles can talk it into reaching another. VpcNetworkBinding trades that away deliberately, and the choice between them is a security decision before it is an ergonomic one.Fetcher, and no invented typeThe binding offers
fetchand nothing else, which isFetcherstructurally — the same reasoning that types BrowserBinding. That matters more here than it did there, because@cloudflare/workers-typesdeclares nothing for Workers VPC at the version this package pins. NamingFetchermeans this class describes no shape of its own while the product is in beta.VpcNetworkBinding could not manage the same trick, and says so.
Example
Author
Bayu Dwiyan Satria
Version
1.0.0
Since
1.3.0