Regionsאזורים
Two regions, both ours. Not a reseller layer on top of someone else's cloud, which is the entire reason data residency here is a fact rather than a contractual assurance. You can bring your own cloud account instead — with a different guarantee, spelled out below.
שני אזורים, שניהם שלנו. לא שכבת משווק מעל ענן של מישהו אחר, וזו בדיוק הסיבה שמיקום הנתונים כאן הוא עובדה ולא הבטחה חוזית. אפשר במקום זאת להביא חשבון ענן משלכם — עם הבטחה אחרת, שמפורטת בהמשך.
The two regionsשני האזורים
il-tlvTel Aviv, Israel. Interhost-operated. The default for Israeli organisations and anyone with an Israeli data-residency requirement.תל אביב, ישראל. מופעל על ידי אינטרהוסט. ברירת המחדל לארגונים ישראליים ולכל מי שיש לו דרישת מיקום נתונים בישראל.nl-amsAmsterdam, Netherlands. Interhost Networks B.V., Serverius facilities. EU jurisdiction, for GDPR-scoped workloads and European latency.אמסטרדם, הולנד. Interhost Networks B.V., מתקני Serverius. שיפוט אירופי, לעומסי עבודה בהיקף GDPR ולזמן תגובה אירופי.Your own cloud accountחשבון הענן שלכם
You can also point Shipyard at an account you already hold on AWS, Google Cloud, Hetzner, Vultr or DigitalOcean. Shipyard deploys and manages the stack there; the invoice, the account and the region stay yours.
אפשר גם להפנות את Shipyard לחשבון שכבר יש לכם ב-AWS, Google Cloud, Hetzner, Vultr או DigitalOcean. Shipyard מפרסם ומנהל שם את הסטאק; החשבונית, החשבון והאזור נשארים שלכם.
In il-tlv and nl-ams we can name the building, because we own the hardware in it. On your own cloud account you get the region you chose from that provider — a real guarantee, but theirs, not ours. The operator is AWS or Google, the jurisdiction follows their terms, and everything above about what stays in region describes what Shipyard does, not what your provider does with it.
ב-il-tlv וב-nl-ams אנחנו יכולים לנקוב בשם הבניין, כי החומרה שבו בבעלותנו. בחשבון הענן שלכם אתם מקבלים את האזור שבחרתם אצל אותו ספק — הבטחה אמיתית, אבל שלו, לא שלנו. המפעיל הוא AWS או Google, השיפוט נגזר מהתנאים שלהם, וכל מה שנאמר למעלה על מה שנשאר באזור מתאר מה Shipyard עושה, לא מה שהספק שלכם עושה עם זה.
Choosing oneבחירת אזור
Region is set per project, in shipyard.yaml, and it is the one field you should get right the first time.
האזור נקבע לכל פרויקט, ב-shipyard.yaml, וזה השדה האחד שכדאי לקלוע בו נכון בפעם הראשונה.
project: api region: il-tlv # or nl-ams
- Where are your users? Latency is the ordinary answer and usually the right one.איפה המשתמשים שלכם? זמן תגובה הוא התשובה הרגילה, ובדרך כלל הנכונה.
- What does your regulator say? Israeli public sector and healthcare generally means il-tlv. GDPR-scoped personal data generally means nl-ams.מה אומר הרגולטור שלכם? מגזר ציבורי ובריאות בישראל בדרך כלל מחייבים il-tlv. מידע אישי בהיקף GDPR בדרך כלל מחייב nl-ams.
- Where is your data already? Putting the application in a different region from its primary database buys you latency you will not enjoy.איפה המידע שלכם כבר נמצא? הצבת האפליקציה באזור שונה ממסד הנתונים הראשי שלה קונה לכם עיכוב שלא תיהנו ממנו.
Changing region on an existing project is rejected. Moving between regions means moving data across a jurisdictional boundary, which is a decision that deserves a plan rather than a config edit. Create a project in the new region, migrate deliberately, then retire the old one. Mail shipyard@interhost.net and we will help.
שינוי region בפרויקט קיים נדחה. מעבר בין אזורים משמעו העברת מידע מעבר לגבול שיפוטי, וזו החלטה שראויה לתוכנית ולא לעריכת קונפיג. צרו פרויקט באזור החדש, העבירו במכוון, ואז הוציאו את הישן משירות. כתבו ל-shipyard@interhost.net ונעזור.
What stays in regionמה נשאר באזור
- Source uploaded by the CLI, and every build artifact produced from it.קוד המקור שהועלה על ידי ה-CLI, וכל תוצר בנייה שנוצר ממנו.
- Running containers and their filesystems.קונטיינרים רצים ומערכות הקבצים שלהם.
- Managed databases, caches and their backups.מסדי נתונים מנוהלים, מטמונים והגיבויים שלהם.
- Application logs and the Turborepo remote cache.לוגים של האפליקציה והמטמון המרוחק של Turborepo.
- Environment variable ciphertext and its encryption keys.הצפנת משתני הסביבה ומפתחות ההצפנה שלה.
What is global: your account identity, organisation membership, billing records and the audit log index. Those are metadata about who you are, not the contents of what you run, and they are stored in the EU.
מה שגלובלי: זהות החשבון שלכם, חברות בארגון, רשומות חיוב ואינדקס יומן הביקורת. אלה מטא-דאטה על מי אתם, לא תוכן מה שאתם מריצים, והם מאוחסנים באיחוד האירופי.
Running in bothריצה בשניהם
Nothing stops you from having an il-tlv project and an nl-ams project in the same organisation, with the same team, the same keys and the same audit trail. That is the usual shape for a company serving both markets: two projects, one pipeline, one place to look.
שום דבר לא מונע מכם להחזיק פרויקט ב-il-tlv ופרויקט ב-nl-ams באותו ארגון, עם אותו צוות, אותם מפתחות ואותו נתיב ביקורת. זו הצורה הרגילה לחברה שמשרתת את שני השווקים: שני פרויקטים, צינור אחד, מקום אחד להסתכל בו.
$ shipyard ps --all PROJECT REGION ENV STATUS RELEASE api il-tlv production ready r_318 api-eu nl-ams production ready r_91
The infrastructure underneathהתשתית שמתחת
Shipyard runs on Interhost’s own network: our address space, our routers, our transit and peering, 1.2 Tbps of capacity, with DDoS mitigation in front of it. When something is wrong at the network layer, the people fixing it work here. There is no upstream provider to open a ticket with and wait.
Shipyard רץ על הרשת של אינטרהוסט: מרחב הכתובות שלנו, הנתבים שלנו, הטרנזיט והפירינג שלנו, 1.2 טרהביט לשנייה של קיבולת, עם הגנת DDoS לפניה. כשמשהו לא בסדר בשכבת הרשת, האנשים שמתקנים אותו עובדים כאן. אין ספק במעלה הזרם שפותחים לו קריאה ומחכים.