openstead
Networking

Private Links

Connect a workspace to a supported external Azure Private Link service with explicit owner approval.

Suggest a change

A Private Link connects your workspace to an external Azure Private Link service over a private endpoint. Use it when the external service publishes an appropriate Azure Private Link resource or alias and its owner can approve the connection.

This is not a general VPN or automatic peering with every cloud database.

Requirements

  • An active qualifying paid service in the workspace.
  • The target's Azure Private Link service resource ID or alias.
  • The TCP port the target service accepts.
  • Approval from the external service owner.
  • Application-level credentials required by that external service.

The connection applies to services in the workspace. Confirm this scope is appropriate before adding a target that holds sensitive data.

Create the connection

Open Connections → Private Links, create a link, and supply its name, description, target resource ID or alias, and TCP port. Save the connection and review its status.

Ask the target owner to review and approve the corresponding endpoint request. Saving a connection in Openstead does not automatically grant permission on the external service.

Wait for an active status and use the verified connection details displayed in the dashboard. A pending or failed status should not be treated as a working private endpoint.

Configure the application

Store the target's authentication credentials in the application's environment variables or secret files. Follow the external provider's client, hostname, TLS, and certificate requirements.

Only the configured allowed port should be used. A successful connection to one target port does not imply general access to the external network.

Review current consumers before changing a target or port. Applications using the link can lose connectivity during a change. Removing a connection removes its managed private-endpoint access; it does not delete the external provider's application or database.

Troubleshooting

Check the target identifier, owner's approval, configured port, and the external service's availability. Then inspect application credentials and DNS requirements. If approval remains pending, the external owner is the right party to confirm it.

For help, send support the connection ID and a redacted description of the target and failure. Do not include authentication secrets or private dataset contents.

Need a hand? Contact Openstead support.

On this page