Private networks and Partner POPs
Private origins
A private origin must remain reachable from selected POPs before activation.
#Overview
A private origin must remain reachable from selected POPs before activation.
#Reach an origin without public exposure
A private origin combines zone, network, address/port, and POPs able to reach it. The platform checks WireGuard readiness and guards against configuration that falls back to a public or unavailable address.
Effective state depends on peers, ACLs, POP profiles, and synchronization. Prepare the domain POPs before activation and keep a representative health check.
#Activate gradually
Enroll the origin in the private network.
Allow only the POP-to-origin port flow.
Prepare and synchronize domain POPs.
Test private health, switch the origin, and monitor.
#Permissions by role
| Action | owner | admin | member | viewer |
|---|---|---|---|---|
| View networks, peers, ACLs, origins, and POPs | Read | Read | Read | Read |
| Create, edit, or delete a network | Allowed | Allowed | Allowed | No |
| Manage peers, enrollment keys, and ACLs | Allowed | Allowed | Allowed | No |
| Link zones, private origins, and POPs | Allowed | Allowed | Allowed | No |
#State lifecycle
| State | Meaning |
|---|---|
configured | Zone, peer, target, and settings are stored. |
active | Routing enabled after network prerequisites pass. |
inactive | Routing deliberately disabled. |
blocked | Readiness, ACL, peer, or POP prevents activation. |