Feature · Network & security
Private networking between your services.
Private networking lets your services talk to each other without going over the public internet. Services in a Runex project reach each other by internal hostname, so your API, workers, and databases never need a public address.
- Internal hostnames
- Databases stay private
- Public only where you choose
- web
- public · https
- api
- api.internal:8080
- postgres
- postgres.internal:5432
- redis
- redis.internal:6379
- exposed
- web only
- network
- private
Definition
What is private networking?
Private networking is an internal network that connects your services to each other and blocks access from outside.
On a public network, every service needs an internet-facing address and its own protection. On a private network, only the services you choose are exposed.
On Runex, every service in a project joins the project's private network. Each gets an internal hostname, and traffic between them never leaves Runex.
Expose only what users need, usually a web frontend or public API. For non-HTTP services that must be reachable from outside, Runex offers a TCP proxy.
How it works
How does private networking work on Runex?
Same project, same private network.
-
You
Add services to a project
A web app, an API, a database, a cache.
-
Runex
Connect them privately
Each service joins the project network.
-
Runex
Assign internal hostnames
Services reach each other by name.
-
You
Choose what's public
Expose only what users need.
Benefits
Why use private networking?
A smaller attack surface, by default.
Databases stay private
No public port for attackers to scan.
Simple service discovery
Call services by name, not by IP.
Lower latency
Traffic stays inside the platform.
Less exposure in transit
Internal calls never cross the internet.
Compare
Private network vs public endpoint: what's the difference?
A public endpoint is reachable by anyone; a private one only by your services.
| Private network | Public endpoint | |
|---|---|---|
| Reachable from | Your project's services only | The whole internet |
| Address | Internal hostname | Public domain or IP |
| Use for | Databases, caches, internal APIs | Websites and public APIs |
| Protection | Isolated by the network | Needs auth, TLS, and rate limits |
Example
Example: a web app, an API, and Postgres
Only the website is public; the API and database talk over the private network.
- Deploy web with a public HTTPS domain
- Deploy api with no public domain
- Create a PostgreSQL database in the same project
- web calls http://api.internal:8080
- api connects to Postgres privately
- Only web is reachable from the internet
- web → api
- api.internal:8080
- api → db
- postgres.internal:5432
- public
- web · https
- private
- api, postgres
- internet → db
- blocked
What is service-to-service communication?
It's how services in the same system call each other, for example a web app calling an internal API. Private networking keeps those calls off the public internet. It is the same setup a full-stack app uses for its frontend, API, and database.
What is internal DNS?
A naming system that only works inside a private network, so services reach each other by name, like api.internal, instead of by IP address.
Should my database be publicly accessible?
Usually not. Keep it on a private network and let only your app connect to it.
What is a TCP proxy?
A proxy that forwards raw TCP traffic, for services that don't speak HTTP, like a game server or a database you must reach from outside.
Next step
Ship with private networking today.
Sign up, install the GitHub App, and deploy your first app. It's free to start.
