| Public (default) | The application is reachable on the public internet. | Adoption-friendly default for customers who do not require a network-isolation boundary. | None directly. Common starting posture for non-regulated customers. |
| Allowlist | The application is public-facing but restricted to a list of customer-supplied IPv4/IPv6 CIDRs. | The customer wants a public path but only from their corporate egress, partner networks, or other known sources. | Demonstrable network-boundary control. Audit-trail friendly: the CIDR list is the documented boundary. |
| Tailscale | The application is reachable only over the customer’s Tailscale network. | The customer already runs Tailscale and wants end users on their tailnet to reach the application. | Eliminates the public path. Tailnet membership becomes the identity-and-authorization boundary the customer’s security team already audits. |