cdn.pizzaDocumentation

Private networks and Partner POPs

Private origins

A private origin must remain reachable from selected POPs before activation.

#Overview

A private origin must remain reachable from selected POPs before activation.

#Reach an origin without public exposure

A private origin combines zone, network, address/port, and POPs able to reach it. The platform checks WireGuard readiness and guards against configuration that falls back to a public or unavailable address.

Effective state depends on peers, ACLs, POP profiles, and synchronization. Prepare the domain POPs before activation and keep a representative health check.

#Activate gradually

  1. Enroll the origin in the private network.

  2. Allow only the POP-to-origin port flow.

  3. Prepare and synchronize domain POPs.

  4. Test private health, switch the origin, and monitor.

#Permissions by role

Actionowneradminmemberviewer
View networks, peers, ACLs, origins, and POPsReadReadReadRead
Create, edit, or delete a networkAllowedAllowedAllowedNo
Manage peers, enrollment keys, and ACLsAllowedAllowedAllowedNo
Link zones, private origins, and POPsAllowedAllowedAllowedNo

#State lifecycle

StateMeaning
configuredZone, peer, target, and settings are stored.
activeRouting enabled after network prerequisites pass.
inactiveRouting deliberately disabled.
blockedReadiness, ACL, peer, or POP prevents activation.
Customer documentationReference generated from published interfaces