Operate cloud systems from the office
Give the operations team access to approved cloud Nodes or Services while the rest of the VPC stays out of scope.
Make authorized Nodes and declared private Services usable across office, cloud, IDC and edge locations. Each environment keeps its own network boundary. Cross-account access uses explicit directional Grants; same-account access to its own Nodes and private Services remains system-provided.
Teams see the resources they are allowed to use, not every address that happens to live at another site.
Give the operations team access to approved cloud Nodes or Services while the rest of the VPC stays out of scope.
Declare the IDC endpoint the team needs rather than making the entire data-center subnet reachable.
Represent machines as Nodes and narrow endpoints as Services across providers instead of inventing a separate access model per cloud.
Bring field and branch devices into the selected Space even when their local network topology differs from site to site.
The product shows each role and scope independently so a ready path is never mistaken for broader network capability.
Cross-account sharing uses a directional L3 Grant for an approved Node, with its host firewall final. Same-account access to its own Node remains system-provided.
Cross-account sharing uses a private L4 Service Grant for an exact protocol, host and port. Same-account access to its own private Services remains system-provided.
Relay, Service Egress, Internet Exit and Public Ingress report readiness independently. One ready role does not imply another.
Each Node and Service is selected explicitly; the surrounding office, cloud, or IDC network does not become reachable by implication.
Model each machine or service inside the Organization and Network that owns its access boundary.
团队看到的是允许使用的资源,而不是恰好位于另一个站点的所有地址。
让运维团队访问获批云节点或服务,VPC 其余范围继续保持不可达。
声明团队真正需要的 IDC 端点,而不是让整个数据中心子网可达。
跨云把机器表示为节点,把窄端点表示为服务,不必为每个云另建访问模型。
即使每个站点本地网络拓扑不同,也能把现场与分支设备纳入当前空间。
产品独立展示每个角色和范围,避免把一条已就绪路径误解成更广泛的网络能力。
跨账号共享对获批节点使用方向明确的 L3 授权,主机防火墙保留终决权;同账号访问自己的节点仍由系统规则提供。
跨账号共享通过私有 L4 服务授权限定准确协议、主机和端口;同账号访问自己的私有服务仍由系统规则提供。
中继、服务出网、互联网出口与公网入口分别报告就绪状态,一个角色就绪不代表另一个角色就绪。
每个节点和服务都被明确选择;周围的办公室、云或 IDC 网络不会因此自动可达。