Network

Private networking

Connect services, databases, and workers over an isolated network with no public exposure.

web-frontend

10.0.4.12

Connected

internal

  • orders-apiInternal
  • app-dbInternal
  • cacheInternal
  • email-workerInternal

Internal traffic stays internal

Every service in a workspace shares a private network out of the box. No VPC diagrams required.

  • No public ports

    Private services and databases are reachable only from inside your network.

  • Stable internal hostnames

    Call other services by name. Addresses stay the same across deploys.

  • Isolated per environment

    Staging, production, and previews each get a separate network.

  • Low-latency links

    Traffic stays inside the region, so calls between services take milliseconds.

How private networking works

Services join the network when they deploy and talk to each other by name.

  • Web service
  • Private service
  • Worker
  • Postgres

Configuration

Declare what is public

Mark a service as private in your config, and reference other services by name in environment variables.

  • Private services have no public URL
  • Connection strings are injected for you
  • Same layout in every environment
          
            
                1
                services:
              
                2
                  - type: web
              
                3
                    name: web-frontend
              
                4
                    envVars:
              
                5
                      - key: ORDERS_API_URL
              
                6
                        fromService:
              
                7
                          name: orders-api
              
                8
                          property: hostport
              
                9
                  - type: private
              
                10
                    name: orders-api
              
                11
                    runtime: go
              
                12
                databases:
              
                13
                  - name: app-db
              
                14
                    publicAccess: false
              
          
        

Why it matters

Most of the traffic in a modern app never needs to leave your infrastructure. An API talks to its database, a worker reads from a queue, and a frontend calls a backend. A private network keeps that traffic off the public internet, which removes a whole class of attack surface and makes every request faster.

What you get

Every workspace has one private network per region and environment. Services join it automatically when they deploy, and they are reachable by a stable hostname that does not change between releases.

  • Encrypted traffic between services
  • Internal DNS for every service and database
  • Public ingress only where you enable it

Connecting from outside

When you need to reach a private service from your laptop, open a short-lived tunnel with the CLI. Tunnels are tied to your account, logged in the audit log, and close automatically when you disconnect.

Free tier · No credit card

Push code today. Be live before your coffee cools.

Connect a repository, pick a region, and get a production URL with HTTPS, logs, and autoscaling already switched on.

$ git push origin main

  1. Build34 s
  2. Deploy12 s
  3. Health checks3 s

your-app.example.com

Buy NowTheme Details