Skip to content

Private Networking ​

Every project gets a default private network automatically — an isolated VXLAN overlay that every resource type (servers, databases, Kubernetes, VPN, API Gateway) can join, so they can talk to each other over private IPs without touching the public internet.

How it works ​

  • Each private network is its own VXLAN segment with hard L2 isolation between tenants — traffic never crosses between different customers' networks, even on the same physical node.
  • A resource attaches to a network as an additional NIC (its primary interface is never moved), so attaching or detaching never disrupts existing connectivity.
  • Networks can span multiple regions/zones — the overlay carries cross-zone traffic over the platform's backbone automatically.

Creating a network ​

  1. Open Networks → Create.
  2. Give it a name and an optional custom IP range (CIDR). Leave it blank to auto-allocate a non-overlapping range.
  3. Save. The network is ready to attach resources to immediately.

Attaching resources ​

From a server, database, Kubernetes cluster or gateway's Networking tab, choose Attach network and pick the network. The resource receives a private IP on that network's range; DNS and routing between attached resources work automatically.

Firewalls ​

Each resource on a private network can have firewall rules scoping which private IPs/ports may reach it — independent of any public-facing firewall or port-forward rules.

Public vs private ​

At creation time, most resource types let you choose whether they get a public IP:

ResourceDefault
VM (server)Your choice
Managed DatabasePrivate only
KubernetesPrivate only
API Gateway / Load BalancerPublic

A private-only resource is reachable only from other resources on the same network (or via VPN — see VPN).

See also ​