> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gcore.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloud egress IP addresses

> Find Gcore Cloud egress IP addresses and ranges to allowlist outbound traffic and automate allowlist updates.

Gcore Cloud services use specific IP addresses for outbound (egress) traffic. The API returns IP address ranges in CIDR notation. If the infrastructure restricts incoming connections by source IP, add these ranges to the allowlist.

## Allowlisting use cases

Add Cloud egress IP ranges to the allowlist in these scenarios:

| Scenario | Description |
| - | - |
| Image and asset delivery | Cloud downloads images or assets from the infrastructure when creating resources. Add egress ranges to the firewall or object storage allowlist so Cloud can fetch files. |
| Webhooks and push integrations | Cloud pushes events to the listener endpoint on subscription to the user-actions event log. Allowlist these ranges to accept traffic only from Cloud. |
| AMQP messaging | Cloud connects to AMQP message brokers for [user-action log subscriptions](/api-reference/cloud#tag/User-Actions). Allowlist these ranges to receive event messages. |
| Security and audit | Use these ranges in SIEM rules or audit tools to verify that traffic originates from Gcore Cloud. |

## Retrieve egress IP ranges

Fetch the current list of Cloud egress IP ranges using the [public API endpoint](/api-reference/cloud#tag/ip-ranges/GET/cloud/public/v1/ipranges/egress). This endpoint requires no authentication.

### Request

```sh theme={null}
curl -i -X GET https://api.gcore.com/cloud/public/v1/ipranges/egress
```

### Response

The response contains an array of IP addresses in CIDR notation covering all Gcore Cloud regions:

```json theme={null}
{
  "ranges": [
    "203.0.113.10/32",
    "203.0.113.11/32",
    "203.0.113.12/32"
  ]
}
```

The list is global and covers all regions. Duplicate prefixes are not returned.

### SDK examples

The Gcore SDKs provide typed methods to retrieve egress IP ranges without manually constructing HTTP requests. The SDK client requires an API key for initialization even though this endpoint is public — set the `GCORE_API_KEY` environment variable before running the examples.

<Tabs>
  <Tab title="Python">
    ```python theme={null}
    from gcore import Gcore

    client = Gcore()  # reads GCORE_API_KEY from environment
    ip_ranges = client.cloud.ip_ranges.list()
    print(ip_ranges.ranges)
    ```
  </Tab>

  <Tab title="Go">
    ```go theme={null}
    package main

    import (
        "context"
        "fmt"

        "github.com/G-Core/gcore-go"
    )

    func main() {
        client := gcore.NewClient()
        ctx := context.Background()
        ipRanges, err := client.Cloud.IPRanges.List(ctx)
        if err != nil {
            panic(err.Error())
        }
        fmt.Printf("%+v\n", ipRanges.Ranges)
    }
    ```
  </Tab>
</Tabs>

## Automate allowlist updates

Gcore continuously expands its network. New IP ranges are added to the list before new infrastructure goes online.

To prevent service disruptions, automate allowlist updates:

```bash theme={null}
#!/bin/bash
# Fetch Cloud egress IPs and update the allowlist.
# The loop body is a placeholder — replace with the command for the target system
# (security group API call, object storage policy update, SIEM rule sync, etc.).

EGRESS_IPS=$(curl -s https://api.gcore.com/cloud/public/v1/ipranges/egress | jq -r '.ranges[]')

for ip in $EGRESS_IPS; do
  # iptables -A INPUT -s $ip -j ACCEPT   # Linux firewall example
  echo "Allowing: $ip"
done
```

<Warning>
  If a new IP range is not added to the allowlist, Cloud instances using that range cannot reach the target systems. Run the update script on a regular schedule — a cron job polling hourly is sufficient for most setups.
</Warning>
