# Network egress and static IPs

import { Aside } from '@astrojs/starlight/components';

Network egress controls the source addresses and datacenters used by outbound
traffic from your Avrea runner VMs. Dedicated static IPs let databases, APIs,
and corporate firewalls allowlist your CI without tracking individual runners.

The Network egress configuration is being enabled per organization. If your
page still shows a single **Static-IP egress** switch, follow the legacy
instructions below or contact Avrea to enable the new configuration.

## Choose your source addresses

Open your organization in the [Avrea console](https://console.avrea.com), then
**Settings** → **Network egress**. An organization Admin can choose:

- **Shared:** use normal runner egress or a shared gateway. Shared routing and
  cross-datacenter transport have no additional charge. A shared address is not
  an organization-exclusive static IP reservation.
- **Dedicated static IPs:** use only your routing-enabled reservations. You can
  reserve several addresses in one datacenter or across supported datacenters.
  Choose a subset when only certain addresses should be used.

Dedicated routing blocks new work when no eligible address is available. It
does not silently switch to shared egress.

## Choose the exit datacenter

| Location policy | Behavior |
| --- | --- |
| Automatic | Prefer the runner's datacenter, then an eligible remote exit. |
| Prefer a datacenter | Try that datacenter first, then the runner's datacenter and eligible fallbacks. |
| Require a datacenter | Use only that exit datacenter; block when unavailable. |

An optional ordered fallback list restricts remote fallback choices. Leaving it
empty uses the platform's gateway priority order. Available locations depend
on deployed gateway and IP capacity. Choosing a remote exit does not move the
runner itself.

Changes apply to new jobs. Running jobs keep their selected source address;
a failed path can require retrying the job. The page shows route previews by
runner datacenter and any active incident override.

## Reserve and enable static IPs

1. Under **Reserved static IPs**, select a supported datacenter and an optional
   name, then choose **Reserve IP**.
2. Copy the address and add it to every external service's source-IP allowlist.
3. Choose **Enable for routing** when those allowlists are ready.
4. Select **Dedicated static IPs** and save the routing policy.
5. Run a workflow against your protected services to verify connectivity.

<Aside type="caution" title="Allowlist every eligible address">
Automatic selection can use any eligible address. Copy and allowlist all
routing-enabled IPs, or select a specific subset in your policy. A newly
reserved address starts disabled for routing so you can prepare allowlists.
</Aside>

## Disable or release an address

**Disable for new jobs** stops new selections while retaining the reservation.
Switching to Shared also retains reservations. These actions do not stop
reservation charges.

**Release** is separate. Avrea drains jobs using the address and waits for
network cleanup before returning it to the pool. Release can remain pending
when a host is unavailable. If you reserve another address later, it may differ
from the released address.

## Traffic scope

The policy covers eligible VM traffic to the public internet. Existing
platform, local cache/proxy, internal-destination and DNS exceptions still
apply; a proxy's upstream request may originate from the host instead of the
VM. External IPv6 is blocked for dedicated gateway paths until routed IPv6 is
supported.

Egress does not create an inbound endpoint. Egress firewall rules and the
destination service's authentication still apply. Shared use of an address by
several jobs does not identify individual repositories or replace application
credentials.

## Availability and billing

Dedicated static IP egress is available with Avrea Enterprise. See
[pricing](https://avrea.com/pricing) or [contact Avrea](https://avrea.com/contact)
for current terms.

Each billable reservation is metered independently for each started UTC day,
including its first day. Charges continue while the address is reserved or
waiting for jobs and network cleanup to drain. Shared gateway use and
cross-datacenter routing do not create a dedicated-IP charge. Explicitly waived
reservations show **No charge**.

## Legacy single-IP configuration

Organizations that have not migrated retain the single **Static-IP egress**
switch under Network egress. Enabling it allocates one address; wait for the
status to become Active, then copy it into your allowlists. Disabling this
legacy switch releases that address, unlike disabling routing in the new
reservation-based configuration.

Migration retains the existing address and enables it for routing. Older
single-IP API and CLI commands cannot represent the new profile; use the
console or the plural `/orgs/{org_id}/static-ips` API after migration.

For help with capacity, pending release or allowlists, contact
[support@avrea.com](mailto:support@avrea.com).

Customer reservations require a configured billing account and remain subject
to your organization's approved static-IP limit. Contact Avrea to change that
limit. Shared routing does not reserve or charge for a dedicated IP.