Layerbeat

Networking and firewall

Use your public IP and allow only the ports your application needs.

Read the server's ipv4 after provisioning completes. Use public addresses for connections between your workspace's servers. The cloud firewall controls inbound access; your operating system and application must also accept the connection.

View rules

curl -sS "$BASE/v1/vms/$VPS_ID/firewall-rules" \
  -H "Authorization: Bearer $LAYERBEAT_API_KEY"

Reading rules requires vm:read. Adding and removing rules requires vm:write.

Open HTTPS

curl -sS -X POST "$BASE/v1/vms/$VPS_ID/firewall-rules" \
  -H "Authorization: Bearer $LAYERBEAT_API_KEY" \
  -H 'Content-Type: application/json' \
  --data '{"protocol":"tcp","port":"443","cidr":"0.0.0.0/0","action":"accept","description":"HTTPS"}'

Use an office or VPN CIDR for services that should be private. 0.0.0.0/0 allows the public internet.

FieldAccepted values
protocoltcp, udp, icmp or all
portOne port, a range such as 8000-8100, or ALL; ignored for icmp and all
cidrSource network; defaults to 0.0.0.0/0
actionaccept or drop; defaults to accept
descriptionA short label, up to 64 characters

An identical rule returns 409 conflict. A server supports at most 100 rules.

Remove a rule

Use the returned rule ID:

curl -sS -X DELETE "$BASE/v1/vms/$VPS_ID/firewall-rules/$RULE_ID" \
  -H "Authorization: Bearer $LAYERBEAT_API_KEY"

Check your current SSH access before removing its rule. If a port remains unreachable, verify that your application is listening on the public interface and that the guest firewall permits it.