Private Networking
Every project gets a default private network automatically — an isolated VXLAN overlay that every resource type (servers, databases, Kubernetes, VPN, API Gateway) can join, so they can talk to each other over private IPs without touching the public internet.
Private network0:44How it works
- Each private network is its own VXLAN segment with hard L2 isolation between tenants — traffic never crosses between different customers' networks, even on the same physical node.
- A resource attaches to a network as an additional NIC (its primary interface is never moved), so attaching or detaching never disrupts existing connectivity.
- Networks can span multiple regions/zones — the overlay carries cross-zone traffic over the platform's backbone automatically.
Creating a network
- Open Networks → Create.
- Give it a name and an optional custom IP range (CIDR). Leave it blank to auto-allocate a non-overlapping range.
- Save. The network is ready to attach resources to immediately.
Attaching resources
From a server, database, Kubernetes cluster or gateway's Networking tab, choose Attach network and pick the network. The resource receives a private IP on that network's range; DNS and routing between attached resources work automatically.
Firewalls
Each resource on a private network can have firewall rules scoping which private IPs/ports may reach it — independent of any public-facing firewall or port-forward rules.
Public vs private
At creation time, most resource types let you choose whether they get a public IP:
| Resource | Default |
|---|---|
| VM (server) | Your choice |
| Managed Database | Private only |
| Kubernetes | Private only |
| API Gateway / Load Balancer | Public |
A private-only resource is reachable only from other resources on the same network (or via VPN — see VPN).