A company-scoped Link tunnel belongs to your company rather than to one workspace, so every workspace in the company can run tests through it. Use one when several teams test the same private environments and you'd rather run and maintain one set of Link Agents than a set per workspace.
This article explains how to set up and manage a company tunnels. To replace existing workspace tunnels with a company tunnel, see Moving workspace tunnels to a company tunnel. Company-scoped tunnels are available with Link 3.0.
Set up a company tunnel
Setting up a company tunnel requires an account admin.
- Open the company dashboard: expand the workspace dropdown in the top right corner of the mabl app and click your company under Manage company.
- Open the API keys tab and click Create key.
- For the key type, choose Link Agent. Give the key a name, set an expiration, and click Create key.
- Copy the key and store it securely. You won't be able to see it again.
- Start a Link Agent with the company key and a tunnel name, the same way you would with a workspace key. See Link Agent setup.
When the agent connects, it appears on the Networking page of the company dashboard, which lists every agent that serves a company tunnel. The Tunnels table shows which workspaces use each tunnel.
For a tunnel that many workspaces share, plan for more capacity than a single workspace needs, and run more than one agent on it. See Sizing and scaling Link Agents.
Manage company tunnels
Account admins manage the agents on a company tunnel from the Networking page of the account dashboard, the same way workspace owners manage workspace agents on Settings > Networking. That includes putting an agent into maintenance mode and shutting it down.
- Access: Account admins choose which roles can reach a company tunnel from the mabl Desktop App and CLI, and whether mabl support can reach it, in the Link tunnel access section of the Networking page. See Controlling access to Link tunnels. For a company tunnel, a role applies to that role in any workspace of your company.
- Activity: Events for company tunnels, such as agents connecting and people accessing the tunnel, appear in the company dashboard's activity feed rather than a workspace activity feed.
Move a workspace tunnel to your company
If a workspace has its own tunnel with the same name as a company tunnel, the company tunnel takes precedence whenever it has a connected agent. Tests in that workspace go through the company tunnel. If the company tunnel has no connected agent, tests fall back to the workspace tunnel.
To move workspaces onto a company tunnel without editing any environment, start a company tunnel with the same name, and traffic moves to it as soon as it connects. When every workspace uses the same name for the same network, one company tunnel takes over all of them. A Link Agent can serve both tunnels while you move, and applies changes to its configuration file without a restart.
For planning the names, the step-by-step move, and how to roll back, see Moving workspace tunnels to a company tunnel.
If a workspace needs a tunnel of its own that the company tunnel should never replace, give the workspace tunnel a different name.
How to tell company tunnels apart from workspace tunnels
Tunnels are identified by name. The mabl Link agent list in an environment, database connection, or deployment event shows company tunnels alongside the workspace's own without marking them.
To check whether a tunnel is a company tunnel, look for it on the Networking page of the company dashboard, which lists every company tunnel and its agents. If a workspace tunnel and a company tunnel share a name, the rule under Move a workspace tunnel to your company decides which one carries the traffic.