Scenarios
IP address allowlist and blocklist access control is used to limit access to model APIs at the gateway layer based on client source IP addresses.
Typical use cases:
Restricted management paths: Management or debugging paths under model APIs are accessible only from Ops network segments, while business inference paths are open to all business network segments.
Blocking abnormal sources: For abnormal calls from specific source IPs or network segments, deny those sources only on the affected paths without impacting other callers.
Note:
This feature operates at the network layer for source IP address determination and is independent of consumer authentication (API Key, JWT, and so on). IP address validation is performed before business authentication, and requests that fail IP address validation do not proceed to subsequent authentication and rate limiting.
Prerequisites
An AI Gateway instance has been created, and it is in the Running state.
The target model API has been created, and the routes or API paths that require control have been identified.
The egress IP addresses or IP network segments of callers have been identified. If callers go through proxies, CLB, or NAT forwarding, confirm the source IP addresses that the gateway actually receives first.
Operation Steps
Step 1: Going to the Access Control Configuration Page
1. Log in to the AI Gateway console. In the instance list, click the target instance name to go to the instance details page. 2. In the left sidebar, go to the Model API Management page. Click the target model API name to go to the details page.
3. Switch to the Access Control tab and go to the IP address access control configuration area.
Step 2: Enabling the Access Policy
In the Edit Access Policy dialog box, turn on the Enable switch.
When IP filtering is enabled, the gateway filters requests to this API by IP address based on the policy configured below. When disabled, the policy does not take effect, and all sources can access the API.
Step 3: Selecting the Policy Type
In Access Policy, select a type. The two options are mutually exclusive:
|
Allowlist | Only IPs on the list are allowed to access, and all sources not on the list are denied. |
Blocklist | Deny access from IPs on the list, and allow all sources not on the list. |
Step 4: Filling in the IP List
Enter the target IP address in the IP field. The rules are as follows:
Multiple IP addresses are supported, separated by English commas.
A single IP address format is supported, such as 127.0.0.1.
The CIDR format is supported.
You can configure up to 400 items.
Step 5: Saving and Taking Effect
Click OK to save the configuration. The configuration takes effect in real time after it is saved, and access control is immediately applied to all requests to the current model API without restarting the gateway or republishing the API.