Private networking
Connect services and databases within an environment without exposing internal endpoints to the internet.
Openstead services can communicate over the private network associated with their environment. Use private addresses for database traffic and internal application calls.
Environment boundaries
Place related services in the same project environment: for example, a web service, worker, and PostgreSQL database in Production. Put staging resources in a separate Staging environment.
The private hostname shown on a service's Connections page is intended for applications in the same environment. A browser or laptop cannot reach it as a public URL. Moving one side of a connection to another environment can break its reachability.
Do not reuse a production database reference for an isolated preview. Give the preview its own appropriate data source and credentials. See Preview environments.
Connect an internal application
Create a private service, configure its listening port, and start it. Copy its private hostname from Connections into the calling application's configuration.
For an internal HTTP service called internal-api listening on port 8000, an application variable might be:
INTERNAL_API_URL=http://internal-api:8000Use the actual hostname displayed by your service. The application must listen on 0.0.0.0 to accept connections from other services, rather than binding only to 127.0.0.1.
Private reachability does not replace application authentication. Authenticate sensitive internal endpoints and validate requests as appropriate for your system.
Connect a managed database
Use connection references for PostgreSQL, MySQL, or Key Value. They keep source selection and variable mapping in Openstead and apply the credentials on the next application deploy.
The database must be running before a dependent deployment can resolve its reference. If it is recovering, wait for the import to finish. If a paid database was paused after expiry, renew it before reconnecting the application.
Public and private entry points
| Service | Internet-facing endpoint | Typical private use |
|---|---|---|
| Web service | Openstead URL and optional custom domains | Application endpoints |
| Static site | Openstead URL and optional custom domains | Not a database or internal process |
| Private service | No public application domain | Internal HTTP/TCP service |
| Database | No public database port | Authenticated database connections |
| Worker or cron | No incoming web endpoint | Outbound calls to internal services |
MySQL's secure phpMyAdmin interface is a browser gateway to a private database, not a published MySQL port.
External network access
For a partner that allowlists your application's public source address, see Outbound IPs. For a supported external Azure Private Link service, see Private Links.
These are different from connecting two Openstead services inside one environment. A third-party private service requires its own target configuration and permission.
Troubleshooting
Check the exact environment, current private hostname, and configured port. Then check whether the destination is running and actually listening on all interfaces. A successful public homepage response does not prove an internal TCP port is configured correctly.
Use an authorised application shell for network checks where available. Do not expose a database to the internet merely to debug an internal connection.