Feature · Network & security

Private networking between your services.

Private networking lets your services talk to each other without going over the public internet. Services in a Runex project reach each other by internal hostname, so your API, workers, and databases never need a public address.

  • Internal hostnames
  • Databases stay private
  • Public only where you choose
project · acme
web
public · https
api
api.internal:8080
postgres
postgres.internal:5432
redis
redis.internal:6379
exposed
web only
network
private
private networkingrunex

Definition

What is private networking?

Private networking is an internal network that connects your services to each other and blocks access from outside.

On a public network, every service needs an internet-facing address and its own protection. On a private network, only the services you choose are exposed.

On Runex, every service in a project joins the project's private network. Each gets an internal hostname, and traffic between them never leaves Runex.

Expose only what users need, usually a web frontend or public API. For non-HTTP services that must be reachable from outside, Runex offers a TCP proxy.

How it works

How does private networking work on Runex?

Same project, same private network.

  1. You

    Add services to a project

    A web app, an API, a database, a cache.

  2. Runex

    Connect them privately

    Each service joins the project network.

  3. Runex

    Assign internal hostnames

    Services reach each other by name.

  4. You

    Choose what's public

    Expose only what users need.

Benefits

Why use private networking?

A smaller attack surface, by default.

Databases stay private

No public port for attackers to scan.

Simple service discovery

Call services by name, not by IP.

Lower latency

Traffic stays inside the platform.

Less exposure in transit

Internal calls never cross the internet.

Compare

Private network vs public endpoint: what's the difference?

A public endpoint is reachable by anyone; a private one only by your services.

Private network vs public endpoint: what's the difference?
Private networkPublic endpoint
Reachable fromYour project's services onlyThe whole internet
AddressInternal hostnamePublic domain or IP
Use forDatabases, caches, internal APIsWebsites and public APIs
ProtectionIsolated by the networkNeeds auth, TLS, and rate limits

Example

Example: a web app, an API, and Postgres

Only the website is public; the API and database talk over the private network.

  1. Deploy web with a public HTTPS domain
  2. Deploy api with no public domain
  3. Create a PostgreSQL database in the same project
  4. web calls http://api.internal:8080
  5. api connects to Postgres privately
  6. Only web is reachable from the internet
private-networking
web → api
api.internal:8080
api → db
postgres.internal:5432
public
web · https
private
api, postgres
internet → db
blocked
illustrative namesrunex

FAQ

Questions developers ask

Short answers about private networking. More in the documentation.

What is service-to-service communication?

It's how services in the same system call each other, for example a web app calling an internal API. Private networking keeps those calls off the public internet. It is the same setup a full-stack app uses for its frontend, API, and database.

What is internal DNS?

A naming system that only works inside a private network, so services reach each other by name, like api.internal, instead of by IP address.

Should my database be publicly accessible?

Usually not. Keep it on a private network and let only your app connect to it.

What is a TCP proxy?

A proxy that forwards raw TCP traffic, for services that don't speak HTTP, like a game server or a database you must reach from outside.

Next step

Ship with private networking today.

Sign up, install the GitHub App, and deploy your first app. It's free to start.