LaserData Cloud
Networking

Access Rules

Permit selected IP ranges and protocols to reach deployment endpoints

Access rules permit selected IP addresses and CIDR ranges to reach deployment endpoints. A CIDR range describes a group of IP addresses. Rules apply to Managed, BYOC, and On-Premise deployments on every plan.

Paid deployments need a rule before clients can connect. Managed Free deployments include the global rule 0.0.0.0/0. It permits every IPv4 address on the enabled protocols, including browser access when HTTP is enabled. Replace it with trusted source ranges before sending application data.

Network access and Cloud permissions are separate. A rule cannot fix a Console deployment:read denial. If your organization owner account is blocked, use the permission troubleshooting steps.

Why Access Rules

Use rules to control the source addresses, protocols, and duration of client access:

  • Permit known office or VPN address ranges.
  • Open TCP for applications and HTTP for monitoring or Stream UI independently.
  • Grant temporary access that expires automatically, for example during contractor work or debugging.
  • Limit Stream UI access to trusted operators' browser IPs.

Concepts

Protocol Rules

Select the protocols that a rule permits for its CIDR ranges. You can enable any combination from the table. A rule without enabled protocols opens no ports, even when it contains address ranges.

ProtocolAPI FieldWhat It Opens
Iggy HTTPiggy_httpIggy HTTP API endpoint (ports 80 and 443)
Iggy TCPiggy_tcpIggy TCP transport
Iggy WebSocketiggy_websocketIggy WebSocket transport
Iggy UDPiggy_udpIggy QUIC/UDP transport

Stream UI loads from the Console and runs in the browser. It connects directly to Warden's HTTP proxy on ports 80 and 443. Enable iggy_http for the browser's IP address. LaserData does not add its own IP to make this connection.

CIDR Blocks

Each rule needs at least one IPv4 CIDR block. Supported forms include these:

  • 203.0.113.5/32 permits one host.
  • 10.0.0.0/16 permits a subnet.
  • 0.0.0.0/0 permits every IPv4 address to use the selected protocols.

Subnet masks must range from /0 to /32.

Rule Expiry

A rule can have a future expiration date. After that date, the rule no longer permits traffic from its address ranges. For example, use expiry to grant a partner 30 days of access without a separate removal task.

Creating an Access Rule

From the Console

  1. Open your deployment's Access Rules tab.
  2. Click Add Rule.
  3. Enter a name that is unique within the deployment.
  4. Add at least one CIDR range.
  5. Select Iggy TCP, HTTP, WebSocket, UDP, or a combination.
  6. If access is temporary, set an expiration date.
  7. Add remarks if you need to explain the rule.
  8. Click Create.

LaserData applies the rule through AWS security groups or GCP firewall rules.

Validation

A new rule must meet these requirements:

  • Its name is unique within the deployment, without regard to letter case.
  • It contains at least one valid IPv4 CIDR block.
  • An expiry date, when supplied, is in the future.
  • The deployment remains within its plan's access-rule limit.

Managing Access Rules

The Access Rules tab lists address ranges, enabled protocols, expiry status, and creation times. Delete a rule to remove it and its corresponding cloud infrastructure configuration. Other active rules retain their permissions.

Plan Limits

ResourceBasicProEnterprise
Access rules per deployment31020

Audit

The audit log records rule creation, updates, and deletion. Creation records identify the requester, CIDRs, and protocols. Update records preserve previous values. Deletion records identify who removed the rule and when.

API Reference

Use API keys for programmatic access. Creating and deleting rules require deployment:access:manage. Listing rules requires deployment:access:read.

Create a Rule

curl -X POST {supervisor_url}/deployments/{deployment_id}/access_rules \
  -H "ld-api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "production-api-access",
    "cidr_blocks": ["10.0.0.0/16", "172.16.0.0/12"],
    "rules": {
      "iggy_tcp": true,
      "iggy_http": true
    },
    "valid_to": "2026-12-31T23:59:59Z",
    "remarks": "Production API servers"
  }'

List Rules

curl {supervisor_url}/deployments/{deployment_id}/access_rules \
  -H "ld-api-key: YOUR_API_KEY"
[
  {
    "id": 1,
    "name": "production-api-access",
    "remarks": "Production API servers",
    "rules": {
      "iggy_http": true,
      "iggy_tcp": true,
      "iggy_websocket": false,
      "iggy_udp": false
    },
    "cidr_blocks": ["10.0.0.0/16", "172.16.0.0/12"],
    "valid_to": "2026-12-31T23:59:59Z",
    "created_at": "2025-01-15T10:30:00Z"
  }
]

Delete a Rule

curl -X DELETE {supervisor_url}/deployments/{deployment_id}/access_rules/{rule_id} \
  -H "ld-api-key: YOUR_API_KEY"

On this page