Streamlit and Snowpark Container Services: public endpoints use per-account hostnames (Pending)

Attention

This behavior change is in the 2026_08 bundle.

For the current status of the bundle, refer to Bundle history.

Public endpoints for Streamlit in Snowflake and Snowpark Container Services use shared hostnames that are not specific to an account. With the 2026_08 bundle enabled, SQL commands return a per-account hostname under snowflake.app for each public endpoint, and the ENABLE_PER_ACCOUNT_APP_SERVICE_URL parameter is withdrawn.

Before the change:

SQL commands return shared hostnames for public Streamlit and Snowpark Container Services endpoints:

SHOW ENDPOINTS IN SERVICE my_service;
-- ingress_url: public-ep-1-host.<...>.snowflakecomputing.app

SELECT VALUE:type::string AS type, VALUE:host::string AS host
  FROM TABLE(FLATTEN(input => PARSE_JSON(SYSTEM$ALLOWLIST())))
  WHERE VALUE:type::string IN ('APP_SERVICE_PUBLIC_WILDCARD', 'STREAMLIT');
-- STREAMLIT | strt2l4rnfogw6vz3aprtv.<deployment>.snowflake.app

Per-account hostnames are available for an individual account by setting ENABLE_PER_ACCOUNT_APP_SERVICE_URL.

After the change:

The same commands return per-account hostnames:

SHOW ENDPOINTS IN SERVICE my_service;
-- ingress_url:             public-ep-1-spcs.myorg-myaccount.us-west-2.aws.snowflake.app
-- privatelink_ingress_url: unchanged

SELECT VALUE:type::string AS type, VALUE:host::string AS host
  FROM TABLE(FLATTEN(input => PARSE_JSON(SYSTEM$ALLOWLIST())))
  WHERE VALUE:type::string IN ('APP_SERVICE_PUBLIC_WILDCARD', 'STREAMLIT');
-- APP_SERVICE_PUBLIC_WILDCARD | *.myorg-myaccount.us-west-2.aws.snowflake.app   (new record)
-- STREAMLIT                   | strt2l4rnfogw6vz3aprtv-sis.myorg-myaccount.us-west-2.aws.snowflake.app

For Snowpark Container Services, the registrable domain changes from snowflakecomputing.app to snowflake.app. The privatelink_ingress_url column is unchanged, and PrivateLink hostnames are covered by a separate behavior change.

Legacy hostnames continue to resolve. SQL commands no longer return them.

How to update your code

If you restrict outbound network access, allow either *.snowflake.app or the account-scoped wildcard record returned by SYSTEM$ALLOWLIST. A policy that allows only snowflakecomputing.app blocks Snowpark Container Services public endpoints after this change. Because the new record contains a wildcard, check that anything that parses SYSTEM$ALLOWLIST accepts wildcard hosts.

If you have hostnames in code or configuration, look them up at runtime instead. For Snowpark Container Services endpoints, read ingress_url from SHOW ENDPOINTS. For Streamlit apps, the STREAMLIT records from SYSTEM$ALLOWLIST carry the current hostnames, and SHOW STREAMLITS returns the app identifier in url_id.

If you embed Streamlit apps in another web application and construct the URL yourself, the organization and account move out of the URL path and into the hostname.

This change is being made to give each account its own hostname namespace, so that Snowflake can manage public endpoints independently per account. For more information, see Snowflake per-account URLs.

Ref: 2451