Skip to content

Access & security

Private and public apps

Choose who can open each app, set your team domain, and control who may make apps public.

Every web app on Elula is either private or public.

ModeWho can open it
PrivateOnly people signed in with a Google account on your workspace's verified team domain
PublicAnyone with the link

Jobs have no URL, so access mode only matters for web apps and APIs.

How private apps work

Private apps are protected by Google Identity-Aware Proxy (IAP) in your own Google Cloud project. When an app is private, Elula turns IAP on for its Cloud Run service and grants your team domain access to it. Visitors sign in with Google before they reach your app. Anyone whose Google account isn't on the team domain is turned away by Google.

When an app is public, Elula turns IAP off and lets anyone call the service.

Right after the first deploy of a private app, access can take 1–2 minutes to take effect. If you see a Google permissions screen, wait and refresh.

Set up your team domain

Private apps need a verified team domain. This is your Google Workspace email domain, such as company.com. Only a workspace owner can add and verify it.

  1. Open Org settings → Access.
  2. Under Team domain, enter your domain and click Add domain.
  3. Add the DNS TXT record Elula shows you at your DNS provider. The record name is _elula-verify.<your-domain> and the value starts with elula-domain-verify=.
  4. Click verify. DNS changes can take a few minutes to show up.
_elula-verify.company.com.  TXT  "elula-domain-verify=<token>"

A domain can be verified by only one workspace. Personal email domains such as gmail.com can't be used.

Before the domain is verified

  • Every new app is public.
  • Any member who can create apps can create public ones.
  • You can't make an app private. Elula shows: "Your workspace's team domain isn't set up yet, so apps can't be private. Ask a workspace owner to set it up, or make the app public."
  • Apps that are already private stay private.

Once you verify the domain, existing private apps open to it without a redeploy.

Changing the team domain

Owners can change a verified team domain from Org settings → Access → Change domain. Elula asks you to confirm because:

  • The old domain loses access to every private app right away.
  • Auto-join turns off.
  • Private apps open to the new domain once you verify it. Until then, new apps are public.

Default access for new apps

In Org settings → Access → Default access for new apps, owners choose Private or Public. This only sets the starting value. You can change access for each app later. Private is only available once the team domain is verified.

Who can make apps public

Owners and admins can always make apps public. For members, owners pick one rule in Org settings → Access → Who can make apps public?:

RuleWhat members can do
Only owners and adminsMembers can't make apps public.
Members, with an owner's approvalMembers request it from the app's settings. An owner or admin approves it in Approvals.
Members, no approval neededMembers make their own apps public straight away.

Every change to these settings is recorded in the audit log.

Change an app's access

In the dashboard, open the app and go to Settings. In the CLI, run these from the app's linked directory:

elula access                  # show the current mode
elula access private          # make it private
elula access public           # make it public (asks for confirmation; -y to skip)
elula access request-public   # ask an owner or admin to approve making it public
elula access withdraw         # withdraw your pending request

If the app is already running, the change is applied to the live service. If it has never been deployed, the setting is saved and applies from its first deploy. Viewers on an app can't change its access.

When an app is made private, any pending requests to make it public are cancelled.

Approve requests

Owners and admins see make-public requests on the Approvals page, or in the CLI:

elula approvals                 # list pending requests
elula approvals approve <id>    # ID or ID prefix
elula approvals deny <id>

When you approve a request, the app becomes public. If it's already running, the change is applied to the running service.