Appearance
Control connector access and IP ranges #
Configure access separately for each Linux host. A support workstation might need SSH to production devices, while a monitoring host needs HTTP to a smaller tagged group. Both use the same organisation-wide device addresses.
Install and connect the host before adding access rules. Use multiple hosts and container workloads to share the same device targets across redundant services and support tools.
Set device and port rules #
In Connectors, open the host and select Edit device rules and ports. Choose Add rule, add one or more existing device tags, enter comma-separated TCP port numbers and choose Save access rules.

A rule matches any of its tags. For example, a single rule containing production and site:brisbane matches production devices anywhere and Brisbane devices, rather than only production devices in Brisbane. Use a dedicated tag for a combined group when that is the scope you need.
| Rule | Tags | TCP ports | Result |
|---|---|---|---|
| 1 | site:brisbane | 22 | SSH to Brisbane devices |
| 2 | role:gateway | 80, 8080 | HTTP ports on gateways |
A Brisbane gateway matches both rules and receives ports 22, 80 and 8080. A Brisbane sensor matching only the first rule receives port 22. Access to one tagged device does not widen another device's ports.
Choose specific ports from 1 to 65535; up to 100 distinct tags and 100 ports per tag are supported per connector. Your plan can restrict that list further. Empty tags/rules grant no device access, and an empty port list grants no services.
The enrolling user's current permission to access devices remains part of authorisation. A tag match alone cannot bypass device permissions or the plan's device allowance. Changes to permissions, plan, tags and connector rules are picked up during the connected host's regular 30-second policy refresh. Removed grants cancel the compliant connector's affected streams. Network changes can briefly interrupt traffic.
Assign and maintain device tags #
From Dataplicity IPs, use Manage device tags to find a device and edit its tags. Saving device tags requires devices.write. Choose clear names that describe the intended access group; the connector rule editor selects existing tags rather than creating new ones.
Adding a matching tag can grant access through every connector whose rules use it. Removing it withdraws that matching rule's access, unless another rule also matches the device. Review the connector rules before changing shared tags.
Find the right address #
Open Dataplicity IPs and search by device name, identity, serial, IP or tag. Copy the address from the device row. Use filters to narrow the inventory. On the installed host, dataplicity-connector devices shows the inventory authorised for that connector.

The dashboard inventory hides devices over the subscription limit. Device allowance is calculated across the organisation, oldest device first, before tag or search filters. Filtering to a smaller group does not change which devices fit the allowance. Over-limit devices retain their identity and assigned IP, but receive no connector routes, DNS answers or TCP access.
A listed address is not a reachability test. Confirm the device is online, inspect the connector's authorised services, and connect to the actual application.
Add address space #
Select IP ranges, then Add IP range. Choose a non-overlapping subnet from the supported address pools. An organisation supports up to 32 ranges. The host checks every range against its existing routes; check LAN, VPN and container address space on all connector hosts before saving.

Existing ranges cannot be edited in place. Adding a range preserves current device addresses; the connector refreshes its network configuration without re-enrollment. Multiple ranges require a connector supporting network configuration version 2. If an installed host reports an upgrade requirement, update it before using multiple ranges. A server showing a fixed single range needs its supported single-range workflow.
Remove a range #
Before selecting a range's remove control:
- Add enough remaining address space to fit the fleet.
- Identify devices currently using the range and the scripts, bookmarks, firewall rules or integrations that refer to their IPs.
- Arrange to update those references when the addresses change. Prefer canonical private DNS names for scripts that should survive an IP reassignment.
- Read the device count and warning in Remove IP range?, then confirm Remove and reassign when ready.
Only devices in the removed range are reassigned. Removal is rejected if remaining ranges cannot fit the fleet, or if the last range is still used by devices or connectors. Existing streams can be interrupted during reconfiguration.
Connector-owned unreachable route guards can remain for retired ranges, preventing stale device addresses from falling through to an unrelated network. Retirement and cleanup explains when to remove them.