openstead
Networking

Private networking

Connect services and databases within an environment without exposing internal endpoints to the internet.

Suggest a change

Openstead services can communicate over the private network associated with their environment. Use private addresses for database traffic and internal application calls.

Environment boundaries

Place related services in the same project environment: for example, a web service, worker, and PostgreSQL database in Production. Put staging resources in a separate Staging environment.

The private hostname shown on a service's Connections page is intended for applications in the same environment. A browser or laptop cannot reach it as a public URL. Moving one side of a connection to another environment can break its reachability.

Do not reuse a production database reference for an isolated preview. Give the preview its own appropriate data source and credentials. See Preview environments.

Connect an internal application

Create a private service, configure its listening port, and start it. Copy its private hostname from Connections into the calling application's configuration.

For an internal HTTP service called internal-api listening on port 8000, an application variable might be:

INTERNAL_API_URL=http://internal-api:8000

Use the actual hostname displayed by your service. The application must listen on 0.0.0.0 to accept connections from other services, rather than binding only to 127.0.0.1.

Private reachability does not replace application authentication. Authenticate sensitive internal endpoints and validate requests as appropriate for your system.

Connect a managed database

Use connection references for PostgreSQL, MySQL, or Key Value. They keep source selection and variable mapping in Openstead and apply the credentials on the next application deploy.

The database must be running before a dependent deployment can resolve its reference. If it is recovering, wait for the import to finish. If a paid database was paused after expiry, renew it before reconnecting the application.

Public and private entry points

ServiceInternet-facing endpointTypical private use
Web serviceOpenstead URL and optional custom domainsApplication endpoints
Static siteOpenstead URL and optional custom domainsNot a database or internal process
Private serviceNo public application domainInternal HTTP/TCP service
DatabaseNo public database portAuthenticated database connections
Worker or cronNo incoming web endpointOutbound calls to internal services

MySQL's secure phpMyAdmin interface is a browser gateway to a private database, not a published MySQL port.

External network access

For a partner that allowlists your application's public source address, see Outbound IPs. For a supported external Azure Private Link service, see Private Links.

These are different from connecting two Openstead services inside one environment. A third-party private service requires its own target configuration and permission.

Troubleshooting

Check the exact environment, current private hostname, and configured port. Then check whether the destination is running and actually listening on all interfaces. A successful public homepage response does not prove an internal TCP port is configured correctly.

Use an authorised application shell for network checks where available. Do not expose a database to the internet merely to debug an internal connection.

Need a hand? Contact Openstead support.

On this page