The binding name and nothing else. Which private host and port the binding
reaches is service_id in wrangler.json, pointing at a VPC Service defined
on the account — so the destination is fixed at deploy time and there is
nothing about it a call could override.
That fixedness is the security property worth keeping. A Worker holding this
binding can reach exactly one private endpoint, and no request it handles can
talk it into reaching another.
Settings for a VPC Service binding.
Remarks
The binding name and nothing else. Which private host and port the binding reaches is
service_idinwrangler.json, pointing at a VPC Service defined on the account — so the destination is fixed at deploy time and there is nothing about it a call could override.That fixedness is the security property worth keeping. A Worker holding this binding can reach exactly one private endpoint, and no request it handles can talk it into reaching another.
Since
1.3.0