Networking & Egress
How Tenki Runners handle egress traffic, shared vs. dedicated IP ranges, and private connectivity options for your CI workloads.
This page describes how Tenki Runners reach the public internet, what egress IP guarantees we offer, and what's possible for private connectivity into your own cloud accounts.
Egress IPs
Tenki operates a dedicated public subnet, a fixed CIDR that all Tenki Runner traffic egresses from. By default, the range is shared across all tenants on the fabric, with multiple runners sharing a single egress IP through NAT.
This means:
- If you need to allowlist Tenki traffic in your downstream services, you can request the current shared egress CIDR using the contact below.
- Multiple runners share a single IP simultaneously by default.
- The egress range is fixed; it does not rotate without prior notice.
Dedicated IP allocation
If you require a dedicated IP block, for example to allowlist only your CI traffic in a partner's firewall, we can sub-allocate a range to your workspace. A dedicated allocation costs $100 per IP per month, and you control how your runners map to IPs within the assigned range.
Private connectivity (PrivateLink, VPC peering)
AWS PrivateLink and VPC peering are not currently configured on our fabric.
That said, our network is built on EVPN/VXLAN across a spine-leaf architecture, which can support private L2/L3 extension. If private connectivity into your AWS (or other cloud) account is a hard requirement for your evaluation, include the target VPC and connectivity model in your request so we can provide a scoping estimate.
Request networking support
For the current shared egress CIDR, a dedicated allocation, or private connectivity, email hello@tenki.cloud with your workspace and any relevant network details.