diff --git a/pages/features/plugins.mdx b/pages/features/plugins.mdx index 7d33f8ce..27ff06a9 100644 --- a/pages/features/plugins.mdx +++ b/pages/features/plugins.mdx @@ -156,6 +156,15 @@ Two consequences follow from `bearer` consulting no user account: - Your platform token stops working on that plugin, so the plugin's token becomes the only way in. - Changing the token takes the same [PATCH path](#adding-plugins-to-an-existing-instance) as adding a plugin, so it lands the next time the instance stops. +{/* vale off */} +:::warning +[Internal communication](/platform/networking#internal-communication) is always enabled on the hosted platform, and operators can enable it on BYOC or on-prem installations. +Where it's enabled, instances of the same user reach each other directly at the network level, which includes each other's plugin ports. +That path doesn't pass through the platform, so nothing checks a plugin authorization token on it: any instance can drive the plugin API of every other instance of the same user. +Treat one account as one trust domain where internal communication is enabled and plugins are running, such as on the hosted platform. +::: +{/* vale on */} + ## Plugin names A plugin name has a maximum length of 63 characters and contains only these characters: diff --git a/pages/platform/networking.mdx b/pages/platform/networking.mdx index 75954277..6fd70e44 100644 --- a/pages/platform/networking.mdx +++ b/pages/platform/networking.mdx @@ -31,6 +31,15 @@ For example, you wouldn't want to expose your database publicly, but you would w Even when using internal communication, scale-to-zero triggers will still work as expected, and your instances will scale down to zero when not in use. ::: +{/* vale off */} +:::warning +Internal communication is always enabled on the hosted platform, and operators can enable it on BYOC or on-prem installations. +Where it's enabled, instances of the same user reach each other directly at the network level, which includes each other's [plugin](/features/plugins) ports. +That path doesn't pass through the platform, so nothing checks a [plugin authorization](/features/plugins#authorization) token on it: any instance can drive the plugin API of every other instance of the same user. +Treat one account as one trust domain where internal communication is enabled and plugins are running, such as on the hosted platform. +::: +{/* vale on */} + Every instance, by default, receives a private IP and a private FQDN (of the format `.internal`). You can see the private IP of your instance by grabbing its details: