ingresses on the create request targets a port the instance listens on, which is why it works on macOS where container exportPorts does not.
ingresses on CreateInstanceRequest is not exposed by the TypeScript SDK at version 1.0.0, which only carries the CreateIngress form, so this step is shown in Go only.HTTP ingress
Declare an HTTP ingress
mode: HTTP makes Namespace terminate TLS and forward cleartext HTTP to the port your workload listens on.Read the allocated hostname
After the instance is ready,
ListIngresses returns the allocated ingresses with their fully qualified names.Call it with a bearer token
The token goes in To make a route reachable without a credential, set
x-nsc-ingress-auth, not in Authorization. This is the single most common mistake when calling an instance endpoint: an Authorization header is ignored and the request is rejected as unauthenticated.doesNotRequireAuth on an httpMatchRule entry with a method and path match. Everything not matched by such a rule still requires authentication.TCP ingress with mTLS
mode: TCP makes Namespace terminate TLS and proxy the raw stream. Client authentication defaults to requiring mTLS, so a client needs a short-lived Namespace client certificate rather than a bearer token.
Read the server name
A TCP endpoint is not addressed by an ingress FQDN. The name to dial comes from
extendedMetadata.tlsBackedPort[].serverName, which requires a DescribeInstance call after the instance is ready.Go
Dial with a client certificate
auth.TenantCertificateSource issues the short-lived certificates, and nstls.ClientConfig builds a tls.Config that presents them.Go
This section is Go only.
nstls.ClientConfig and auth.TenantCertificateSource have no TypeScript equivalent in the published SDK. The underlying RPCs, IssueTenantClientCertificate and ExchangeTenantTokenForClientCert, are available to any client willing to assemble the TLS configuration itself.Source
go/macoshttps and go/macosmtls in github.com/namespacelabs/examples.
See ingress for the ingress model and access controls for the full authentication matrix.