GitHub Actions and CI
Deploy jobs and test suites that reach a firewalled database, a package registry or a partner API. Set the proxy only on the steps that need the fixed IP.
Static egress · France (GRA) or Germany (LIM)
Allowlist one IPv4 address on your database, partner API or firewall. Send your workflows, agents and jobs out through it, using an authenticated HTTPS CONNECT proxy (TLS to the proxy) or WireGuard, with a destination allowlist you control.
Starter $39 / month, Pro $79 / month, excl. VAT. 30-day paid pilot, best effort, no SLA.
203.0.113.25
France (GRA) or Germany (LIM)
Example address from a documentation range.
Many databases, partner APIs and corporate firewalls only accept traffic from IP addresses you register in advance. GitHub-hosted runners, serverless functions and cloud-hosted jobs run from large pools of addresses that change, so there is no single IP to register.
The usual answers are a NAT gateway with a fixed address in your own cloud account, self-hosted runners, or a platform add-on. They work, but they cost real money or real maintenance time, and they differ on every platform you use.
Static egress gives every one of those workloads the same dedicated address, whatever platform it runs on.
Deploy jobs and test suites that reach a firewalled database, a package registry or a partner API. Set the proxy only on the steps that need the fixed IP.
Agents, MCP servers and automations that call APIs which check the caller’s IP. Your customer allowlists one address, whatever the agent platform runs on.
Cron jobs, queue workers and functions on platforms that give you a changing pool of addresses. One source IP for all of them.
Integrations where the other side asks for “the IP addresses we will connect from” before they open a port. Hand them yours, and keep it when you change hosting.
Starter gives you one dedicated IPv4 in France (GRA) or Germany (LIM), your choice. Pro gives you two, one in each country. Then list the hosts and CIDR ranges your jobs need to reach: that is your destination allowlist.
We assign the IPv4 address to your workspace and send you proxy credentials, a WireGuard config, or both.
Give the address to the database or partner. Set HTTPS_PROXY or bring up the WireGuard tunnel. Your traffic now leaves from that one IP.
Proxy credentials and WireGuard details arrive by email when your order is confirmed. Values below are examples: addresses come from documentation ranges, and USER, PASSWORD and PROXY_HOST are placeholders.
HTTPS_PROXY secretStore the proxy URL as a repository or environment secret and set it only on the step that calls the allowlisted service.
name: nightly-sync
on:
schedule:
- cron: "0 3 * * *"
jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Call the partner API from the dedicated IP
env:
# The secret looks like https://USER:PASSWORD@PROXY_HOST:HTTP_PORT
HTTPS_PROXY: ${{ secrets.EGRESS_PROXY_URL }}
run: |
curl -sS --fail https://api.partner.example/v1/sync
The proxy URL starts with https://: the connection to the proxy is TLS, so the login is not readable on the way. Use the node's DNS name as the host, so the certificate matches. DNS lookups happen on our side. Check the address the other side sees with any IP echo service on your allowlist.
curl --proxy https://USER:PASSWORD@PROXY_HOST:HTTP_PORT https://api.ipify.org
# prints your dedicated IP, for example 203.0.113.25
Clients such as psql do not speak HTTP proxies. Bring up a WireGuard tunnel that routes only the database address, and the connection leaves from your dedicated IP.
[Interface]
PrivateKey = <your-private-key>
Address = 198.51.100.2/32
[Peer]
PublicKey = <penduses-public-key>
Endpoint = <endpoint-from-your-welcome-email>:51820
# Only the database address goes through the tunnel:
AllowedIPs = 203.0.113.10/32
PersistentKeepalive = 25
sudo wg-quick up ./penduses-egress.conf
psql "host=203.0.113.10 dbname=app user=app sslmode=require"
Serverless and AI jobs: set HTTPS_PROXY as an environment variable. Many HTTP clients read it (curl, Python requests, Go net/http); others need a proxy option set in code, so check your client’s documentation.
Two EU locations at launch: Gravelines, France (GRA) and Limburg, Germany (LIM).
Your dedicated IPv4 sits in France (GRA) or Germany (LIM). Choose the one closer to the services you call, or the country your counterparty expects. The location is fixed once the address is assigned; changing it later means a new address.
Pro gives you one dedicated IPv4 in France (GRA) and one in Germany (LIM). Allowlist both. Failover is on your side: your jobs try one address and fall back to the other. We do not switch traffic for you, there is no automatic failover, and the pilot has no SLA.
Try the first endpoint and fall back to the second. Both proxy URLs are secrets you store yourself.
for proxy in "$EGRESS_PROXY_FR" "$EGRESS_PROXY_DE"; do
if curl -sS --fail --max-time 20 --proxy "$proxy" https://api.partner.example/v1/sync; then
break
fi
done
What you control, what we do, and what we do not do.
You give us the hosts and CIDR ranges your jobs reach, by email or in your dashboard once it is live. Anything else is refused at the egress node, and so are internal RFC 1918 ranges, loopback and cloud-metadata addresses. An “open” mode without a fixed list can be enabled after 14 days and a manual review.
Proxy access needs credentials that belong to your workspace, so only your jobs use your IP. Ask us to rotate them whenever you need. WireGuard tunnels are authenticated with keys.
HTTPS stays encrypted between your client and the destination, and we do not inspect payloads. We keep connection metadata for 30 days to run the service and handle abuse reports. Details are in the privacy draft.
The proxy login is a username and password. Choose WireGuard when you want the whole path between your host and our egress node encrypted. This is not a tool for hiding who you are: traffic is tied to your account, and the acceptable use policy applies.
Per month, excl. VAT. Traffic figures are fair-use allowances, not unlimited.
$39 / month, excl. VAT
$79 / month, excl. VAT
Yes. The address is assigned to your workspace and no other customer uses it. Starter includes one address, Pro includes two, one in each country.
Gravelines, France (GRA) or Limburg, Germany (LIM). With Starter you choose one when you order; with Pro you get one address in each. Other locations may follow, and nothing beyond that is promised yet.
You get two addresses in two countries and switch between them yourself, in a script or in the GitHub Action we are about to publish. We do not fail over for you and the pilot has no SLA. Remember to allowlist both addresses at the destination. How Pro failover works.
Yes. Any job that can set HTTPS_PROXY or run WireGuard can use it. Set the proxy only on the steps that need the fixed IP, so that unrelated downloads do not have to be on your destination allowlist.
TCP destinations on your allowlist through the HTTPS CONNECT proxy, and whatever you route into the WireGuard tunnel. Send us the hosts and CIDR ranges you need.
Tell us and we will look into it. We cannot promise that any third party will accept an address, which is why the pilot is a way to test your real destinations first.
No. We do not decrypt or inspect payloads. We log connection metadata (time, destination, port, bytes) for 30 days.
The traffic amounts on the plan are what we plan capacity around. If you get close to or go past them we will email you first to talk it through, unless the traffic harms other customers or breaks the acceptable use policy.
No. Read the acceptable use policy before ordering. Abuse reports go to abuse@penduses.com.