1. get list of customer netblocks
2. setup "internal" service(s) for customers
3. setup firewall rules to allow customer <-> service allow list
4. setup DNS records
5. tell customers DNS and API targets