Access & security
Private and public apps
Choose who can open each app, set your team domain, and control who may make apps public.
Every web app on Elula is either private or public.
| Mode | Who can open it |
|---|---|
| Private | Only people signed in with a Google account on your workspace's verified team domain |
| Public | Anyone with the link |
Jobs have no URL, so access mode only matters for web apps and APIs.
How private apps work
Private apps are protected by Google Identity-Aware Proxy (IAP) in your own Google Cloud project. When an app is private, Elula turns IAP on for its Cloud Run service and grants your team domain access to it. Visitors sign in with Google before they reach your app. Anyone whose Google account isn't on the team domain is turned away by Google.
When an app is public, Elula turns IAP off and lets anyone call the service.
Set up your team domain
Private apps need a verified team domain. This is your Google Workspace email domain, such as company.com. Only a workspace owner can add and verify it.
- Open Org settings → Access.
- Under Team domain, enter your domain and click Add domain.
- Add the DNS TXT record Elula shows you at your DNS provider. The record name is
_elula-verify.<your-domain>and the value starts withelula-domain-verify=. - Click verify. DNS changes can take a few minutes to show up.
_elula-verify.company.com. TXT "elula-domain-verify=<token>"
A domain can be verified by only one workspace. Personal email domains such as gmail.com can't be used.
Before the domain is verified
- Every new app is public.
- Any member who can create apps can create public ones.
- You can't make an app private. Elula shows: "Your workspace's team domain isn't set up yet, so apps can't be private. Ask a workspace owner to set it up, or make the app public."
- Apps that are already private stay private.
Once you verify the domain, existing private apps open to it without a redeploy.
Changing the team domain
Owners can change a verified team domain from Org settings → Access → Change domain. Elula asks you to confirm because:
- The old domain loses access to every private app right away.
- Auto-join turns off.
- Private apps open to the new domain once you verify it. Until then, new apps are public.
Default access for new apps
In Org settings → Access → Default access for new apps, owners choose Private or Public. This only sets the starting value. You can change access for each app later. Private is only available once the team domain is verified.
Who can make apps public
Owners and admins can always make apps public. For members, owners pick one rule in Org settings → Access → Who can make apps public?:
| Rule | What members can do |
|---|---|
| Only owners and admins | Members can't make apps public. |
| Members, with an owner's approval | Members request it from the app's settings. An owner or admin approves it in Approvals. |
| Members, no approval needed | Members make their own apps public straight away. |
Every change to these settings is recorded in the audit log.
Change an app's access
In the dashboard, open the app and go to Settings. In the CLI, run these from the app's linked directory:
elula access # show the current mode elula access private # make it private elula access public # make it public (asks for confirmation; -y to skip) elula access request-public # ask an owner or admin to approve making it public elula access withdraw # withdraw your pending request
If the app is already running, the change is applied to the live service. If it has never been deployed, the setting is saved and applies from its first deploy. Viewers on an app can't change its access.
When an app is made private, any pending requests to make it public are cancelled.
Approve requests
Owners and admins see make-public requests on the Approvals page, or in the CLI:
elula approvals # list pending requests elula approvals approve <id> # ID or ID prefix elula approvals deny <id>
When you approve a request, the app becomes public. If it's already running, the change is applied to the running service.