Environment Isolation
Environment Network Isolation
When an internal request is made between platform nodes, the system checks whether the requesting and requested environments belong to the same isolated group. The request is allowed only when the configured isolation rules permit the connection.
Private Network Isolation
When Network Isolation is enabled for the platform, user accounts are isolated from one another by default. Environments owned by different accounts cannot communicate through the internal network unless access is explicitly configured at both ends.
The same feature can also separate groups of environments within one account. This is useful when several unrelated applications or projects are hosted under the same account.
Enable Isolation for an Environment Group
Open the Add Group or Edit Group dialog and turn on the Network Isolation switch.
How Isolation Works
The platform automatically collects the private IP addresses of containers inside each isolated group and places them into a dedicated IP set.
The platform automatically updates these IP sets when related account changes occur, including environment removal and horizontal node scaling.
Important Considerations
- Network Isolation can be enabled only for a top-level environment group, not for a nested subgroup.
- Isolated groups display a shield icon for easier identification.
- A collaborator cannot add a shared environment to an isolated group.
- The feature controls internal platform networking only.
- It does not restrict access from outside the platform through a public IP address or another external entry point.
Using Network Isolation
Network Isolation helps prevent unwanted internal access between applications and projects hosted under one account.
By placing unrelated projects into separate isolated groups, the platform prevents accidental or undesired internal interconnections between them.
What’s next?
- Environment Groups
- Container Firewall
- Shared Load Balancer
- Public IP
- Endpoints
