<!-- zibby-template-version: 4 -->
# /zibby-static-ip — set up dedicated outbound static IP for an agent

You are helping the user route an agent's outbound traffic through a static IP address — needed when the agent calls APIs that require IP allowlisting (corporate GitLab/GitHub Enterprise, internal SaaS, firewalls).

Canonical docs: **https://docs.zibby.app/workflows/egress**

> Note: the `--dedicated-ip` flag lives on the legacy alias `zibby deploy <name>`, NOT on `zibby agent deploy <name>`. The two share a handler, but only `zibby deploy` exposes this flag in `--help`.

## What "static IP" means here

By default, agent tasks run on shared infrastructure and their outbound traffic exits via managed IPs that rotate. With the **dedicated egress** addon enabled, the agent's outbound traffic is routed through a Zibby-managed proxy whose IP is pinned and customer-allowlistable.

Two pieces:
1. **Account-level addon** — `~$50/mo`, requires Pro subscription. One-time toggle per account.
2. **Per-agent opt-in** — once the addon is on, each agent opts in individually (some agents might not need it, no point routing them).

## Steps

1. **Confirm the user understands the cost.** Before any `--dedicated-ip enable`, explicitly say:
   ```
   "This will enable a $50/mo dedicated-egress addon on your account. Confirm?"
   ```
   If they don't have a Pro subscription, the enable call returns 402 — direct them to https://zibby.dev/billing first.

2. **Check current state:**
   ```
   Bash(zibby deploy <name> --dedicated-ip status)
   ```
   Output tells you: addon active or inactive, this agent currently using it or not, and the assigned IPs to publish to customers.

3. **If addon is inactive — enable it** (only after explicit user confirmation):
   ```
   Bash(zibby deploy <name> --dedicated-ip enable)
   ```
   This is one-time per account. After this, the addon is active for ALL agents in the account that opt in.

4. **Opt this agent in:**
   ```
   Bash(zibby deploy <name> --dedicated-ip use)
   ```
   From now on, every deploy of this agent + every triggered execution routes outbound through the static IP.

5. **Re-deploy the agent** so the runtime picks up the change:
   ```
   Bash(zibby agent deploy <name>)
   ```

6. **Verify in a node** by adding a quick log:
   ```js
   ctx.log(`HTTP_PROXY=${process.env.HTTP_PROXY}`);
   ```
   The proxy URL should be set on the node's process. The IP that external services see is the dedicated one.

## Reverting

- `Bash(zibby deploy <name> --dedicated-ip unuse)` — stop routing this agent's egress through the static IP. Other opted-in agents are unaffected.
- `Bash(zibby deploy <name> --dedicated-ip disable)` — disable the addon entirely (also stops billing).

## Tell the user the IPs

After `enable`, the assigned outbound IPs are visible in `--dedicated-ip status` output. Surface them clearly so the user can paste into their customer's firewall allowlist:
```
Outbound static IPs (allowlist these in the customer's firewall):
  54.252.121.111
```

## Don't confuse with the inbound static IPs

This is OUTBOUND (agent → external API). There's also an INBOUND static-IP set for `https://logs-stream.zibby.app` (the SSE log endpoint customers tail with `zibby agent logs -t`). That one is unrelated to this addon — see `https://docs.zibby.app/security/ip-allowlist`.
