The binding name and nothing else. The network reached is network_id or
tunnel_id in wrangler.json; the destination within it is chosen per call,
which is what separates this from a VPC Service.
There is deliberately no allowlist setting here. Constraining which private
destinations a Worker may reach is worth doing, and this is the wrong layer
to do it — an accessor that filtered addresses would be a security control
enforced in library code a caller can route around by resolving the binding.
Cloudflare's own answer is to bind a VPC Service per destination instead.
Settings for a VPC Network binding.
Remarks
The binding name and nothing else. The network reached is
network_idortunnel_idinwrangler.json; the destination within it is chosen per call, which is what separates this from a VPC Service.There is deliberately no allowlist setting here. Constraining which private destinations a Worker may reach is worth doing, and this is the wrong layer to do it — an accessor that filtered addresses would be a security control enforced in library code a caller can route around by resolving the binding. Cloudflare's own answer is to bind a VPC Service per destination instead.
Since
1.3.0