openstead
Services

Private services

Run internal application services without exposing a public website.

Suggest a change

A private service runs an application that other permitted Openstead services can reach through private networking. Use it for an internal API or a backend component that should not have a public HTTPS endpoint.

Create a private service

  1. Create a Private Service in the same project and network scope as its clients.
  2. Select the repository or container image and configure its build and start commands.
  3. Choose a paid instance plan and add required variables.
  4. Confirm that the application's listening port matches the service configuration. Use Update service to set configuration.port and an optional configuration.healthCheckPath for an internal HTTP application.
  5. Deploy, then copy the private hostname from the service's connection details.

The server must bind to 0.0.0.0, not only 127.0.0.1. For an internal HTTP API listening on port 8000, its clients use a URL shaped like http://<private-host>:8000.

Connect from another service

Store the private URL in the calling service's environment, such as INTERNAL_API_URL. The actual hostname must come from Openstead's connection details. A browser on a customer's laptop cannot resolve or connect to this private address.

Read Private networking before connecting across projects or isolated environments. Placing resources in the same workspace does not mean every isolation boundary is removed.

Keep authentication where it matters

Private reachability controls network access. Your application should still authenticate requests that can read sensitive records or change state. Use narrowly scoped credentials between services and apply request timeouts so a slow dependency does not exhaust the caller's connections.

Deploy and scale

Private services use the same build lifecycle, logs, and paid compute options as web services. Stateless instances can use manual or automatic scaling. A service with a persistent disk is restricted to one instance.

Choose a background worker instead when the process consumes a queue and does not need to accept network requests. Choose a web service when the application needs a public URL or a custom domain.

Need a hand? Contact Openstead support.

On this page