Skip to main content
Available on Enterprise plans as an add-on.
By default, Deck picks the IP address that gives each task run against a source the best chance of succeeding. For sources that only accept allowlisted IP addresses, static IPs send every task run from a fixed range owned by Deck. Static IPs are a setting on the source. Every credential, task, trigger, and task run against the source inherits it. If the static IP range is unavailable, task runs against the source can fall back to Deck’s default IPs. Those task runs come from addresses outside the range, so a source that enforces its allowlist may reject them.

Turning static IPs on

Turn on the Static IPs toggle on the source’s detail page in the Console, or set network on POST /sources or PATCH /sources/{source_id}:
network is always returned on the source. A source using static IPs also carries the range under network.static_ips:
To turn static IPs off, send "network": { "type": "default" }. Omitting network on create gives the source Deck’s default network, and omitting it on update leaves the setting unchanged.

Getting the range

The range is available from the Console and the API. In the Console, it appears on the source’s detail page once static IPs are on. To get it before you turn static IPs on, so the source’s allowlist is in place before the first task run, call GET /static-ips:
cidr is the range to allowlist, and it’s the same for every source in your organization. Allowlist the whole range, since the specific addresses your runs use can change at any time. cidr is omitted until static IPs are enabled for your organization.

Range changes

Deck gives 30 days’ notice before changing the range. From the start of the notice window, the API returns the new range, and the old range keeps working until the window closes. A session never changes IP address during its lifetime.

Errors

Any of the following returns invalid_field_value:
  • A network.type other than default or static_ips.
  • network.static_ips on create or update. The range is read-only.
  • A session_id from a session that didn’t start on static IPs, used for a static-IP source. Start a new session instead.
Setting network.type to static_ips before static IPs are enabled for your organization returns feature_not_available.