Appearance
Cloud and regions
xgress3 runs on Microsoft Azure. Each production region is an independent Azure deployment. Agents, services, and caller traffic stay within the region you select.
Regions
| Region slug | Azure region | Location |
|---|---|---|
au | Australia East | Sydney |
us | East US | Virginia |
eu | West Europe | Netherlands |
sg | Southeast Asia | Singapore |
Choose the region closest to your backends and typical callers. An agent is bound to one region for its lifetime; services inherit that region.
Hostnames
Regional platform endpoints use the region slug:
text
https://{region}.xg3.ioTenant service hostnames include the same slug:
text
https://{account_id}--{service_id}.{region}.xg3.io/{path}Example (Australia): https://acme--api.au.xg3.io/v1/health
See Overview for how requests flow through the regional gateway and agent.
Planned maintenance
Each region has a reserved weekly window: Monday, 3:00am–7:00am in that region’s local morning (for example, Monday 3:00am–7:00am in Sydney for au).
That is a slot, not a standing outage. xgress3 applies regional platform and security updates only when an update is ready. Many Mondays pass with no change and no disruption. When an update is needed, it runs inside this window — not at an arbitrary weekday hour.
Windows are per region. Maintenance in au does not affect us, eu, or sg.
What to expect when an update runs
- Agent tunnels in that region may drop for a short period. The xg3 Agent reconnects on its own (exponential backoff, no operator action). See Agent operations — Reconnection.
- In-flight HTTP to
https://{account}--{service}.{region}.xg3.io/...may fail (connection reset or 504AGENT_UNAVAILABLE) until the tunnel is back. Callers should retry with backoff. - The console and regional apex (
https://{region}.xg3.io— token mint, JWKS) may be briefly unavailable in the same window. - Configuration is unchanged — enrollment, services, credentials, and service keys are not reset. Agents do not need to re-enroll.
Disruption is typically minutes, not the full four-hour slot. The 3:00am–7:00am range is the outer bound so work can finish without spilling into the business day.
What you should do
- Treat Monday 3:00am–7:00am local to your region as a possible brief blip when designing client retries and on-call runbooks.
- Do not schedule your own production cutovers to depend on zero gateway disruption in that slot.
- If an agent stays disconnected well after 7:00am, treat it as an incident — check the process, outbound HTTPS to
https://{region}.xg3.io, and Troubleshooting.