If your workspace runs tests over mabl Link, your cloud runs can always use its tunnels. Members of your mabl workspace and mabl support can only send their own traffic through a tunnel, to train tests or run them locally against the applications inside your network, if you allow it. This article explains who can reach your tunnels, how to allow members of your team or mabl support, and how to turn on personal Link tunnels. These settings are available with Link 3.0.
What is always allowed
API keys, cloud runs, and cloud agents are always allowed to use a workspace's tunnels. Tests that run in the mabl cloud over mabl Link keep working however you configure the settings in this article.
The settings here control access for people, when they reach a tunnel from their own computer. A person needs access to:
- Train a test over a Link tunnel in the mabl Desktop App
- Run Link connection diagnostics from the Desktop App or with
mabl link-agents testin the mabl CLI - Open a local port into a tunnel with
mabl link-agents bridge
Where to find the settings
| Tunnels | Location | Who can change the settings |
|---|---|---|
| Workspace tunnels | Settings > Networking > Link tunnel access | Workspace owners |
| Company tunnels | Networking > Link tunnel access in the company dashboard | Account admins |
Everyone else sees the settings but can't change them.
Trial workspaces
A new trial workspace starts with Company admins and Workspace owners allowed, and with support access and personal tunnels turned on. Every other workspace starts with all of these settings off.
Allow your team to reach tunnels
Under Team access, choose the roles that can reach the tunnels from the mabl Desktop App and CLI in Roles allowed to access Link tunnels:
- Company admins
- Workspace owners
- Workspace editors
- Workspace viewers
For a workspace tunnel, a workspace role means that role in the workspace. For a company tunnel, it means that role in any workspace of your company.
No role is allowed until you choose one. Allow only the roles that need to reach your private services directly, since anyone in an allowed role can send traffic into your network through the tunnel.
Allow mabl support to reach tunnels
To let the mabl support team reach your tunnels while they help you troubleshoot, turn on Allow mabl support to access Link tunnels under Support access. The setting is off until you turn it on.
With support access on, mabl support can reach the services behind your tunnels the way an allowed member of your team can. For example, they can run connection diagnostics through a tunnel, or train a test over it, to reproduce the problem you reported. Consider turning support access on while mabl is helping you with a Link issue and off again afterwards. When mabl support starts a session on a tunnel, it appears in your activity feed.
Allow personal Link tunnels
A personal Link tunnel runs on a team member's own computer and routes their cloud runs through it. To allow them in a workspace, a workspace owner turns on Allow personal Link tunnels under Personal tunnel access. The setting is off until you turn it on, and it only exists for workspaces.
Review who accessed a tunnel
Access to your tunnels appears in the activity feed: Settings > Activity feed for workspace tunnels, and the company dashboard's activity feed for company tunnels. Filter by the link tunnel access entity type to see:
- Who accessed a tunnel, and whether they used an API key
- Connections that were denied
- Sessions that mabl support started on a tunnel
To keep the feed readable, repeat connections by the same person are recorded once per hour.
If someone is denied access
A person who isn't allowed sees an error in the mabl Desktop App or CLI saying they don't have access to the tunnel. The error names the settings to change: Settings > Networking > Link tunnel access for a workspace tunnel, or the company dashboard's Networking > Link tunnel access for a company tunnel.
To give them access, a workspace owner or account admin adds their role to Roles allowed to access Link tunnels. The change applies to their next connection.