Why it matters
Most of the traffic in a modern app never needs to leave your infrastructure. An API talks to its database, a worker reads from a queue, and a frontend calls a backend. A private network keeps that traffic off the public internet, which removes a whole class of attack surface and makes every request faster.
What you get
Every workspace has one private network per region and environment. Services join it automatically when they deploy, and they are reachable by a stable hostname that does not change between releases.
- Encrypted traffic between services
- Internal DNS for every service and database
- Public ingress only where you enable it
Connecting from outside
When you need to reach a private service from your laptop, open a short-lived tunnel with the CLI. Tunnels are tied to your account, logged in the audit log, and close automatically when you disconnect.