Skip to main content
Instance endpoints are authenticated by default. Reaching one is not a matter of fetching a URL: an HTTP ingress expects a bearer token in a Namespace-specific header, and a TCP ingress expects a client certificate. Declaring ingresses on the create request targets a port the instance listens on, which is why it works on macOS where container exportPorts does not.
ingresses on CreateInstanceRequest is not exposed by the TypeScript SDK at version 1.0.0, which only carries the CreateIngress form, so this step is shown in Go only.

HTTP ingress

1

Declare an HTTP ingress

mode: HTTP makes Namespace terminate TLS and forward cleartext HTTP to the port your workload listens on.
2

Read the allocated hostname

After the instance is ready, ListIngresses returns the allocated ingresses with their fully qualified names.
3

Call it with a bearer token

The token goes in x-nsc-ingress-auth, not in Authorization. This is the single most common mistake when calling an instance endpoint: an Authorization header is ignored and the request is rejected as unauthenticated.
To make a route reachable without a credential, set doesNotRequireAuth on an httpMatchRule entry with a method and path match. Everything not matched by such a rule still requires authentication.

TCP ingress with mTLS

mode: TCP makes Namespace terminate TLS and proxy the raw stream. Client authentication defaults to requiring mTLS, so a client needs a short-lived Namespace client certificate rather than a bearer token.
1

Declare a TCP ingress

Go
2

Read the server name

A TCP endpoint is not addressed by an ingress FQDN. The name to dial comes from extendedMetadata.tlsBackedPort[].serverName, which requires a DescribeInstance call after the instance is ready.
Go
3

Dial with a client certificate

auth.TenantCertificateSource issues the short-lived certificates, and nstls.ClientConfig builds a tls.Config that presents them.
Go
This section is Go only. nstls.ClientConfig and auth.TenantCertificateSource have no TypeScript equivalent in the published SDK. The underlying RPCs, IssueTenantClientCertificate and ExchangeTenantTokenForClientCert, are available to any client willing to assemble the TLS configuration itself.

Source

go/macoshttps and go/macosmtls in github.com/namespacelabs/examples. See ingress for the ingress model and access controls for the full authentication matrix.
Last modified on October 2, 2026