Initially, a container is only accessible within the project. It becomes reachable from outside via a reachability: as a web address via our central proxy with an SSL certificate, or as a dedicated TCP or UDP port for services that do not require a browser. You can configure both options when creating the container using the wizard, or later on the container’s page in the Reachability tab.
Setting up a web address with SSL
- Open the container and go to the Reachability tab.
- If the container has only been accessible internally so far, click Release anyway …; otherwise click Add reachability.
- Select Web (HTTPS) and enter the port in the container - the port on which the application in the container is listening; for WordPress, for example, this is 80.
- Only enable ‘Container speaks HTTPS’ if the application itself responds encrypted. Adjust the maximum upload size if necessary.
- Save.
Your address consists of the container name, project ID and base domain, for example wordpress-cms3oepx8.apps.pod01.speedit.solutions. We issue the SSL certificate automatically and renew it in good time.
The check chain
For each address, the check chain shows whether everything is working correctly right up to the application:
- Address - the DNS record points to our server.
- Certificate - valid and automatically renewed.
- Container - running.
- Application - responds on the port, for example with status 200.
Click Test now to check the application again; the time of the last test is shown below. Typical results:
- Responds with status 5xx - the address works, but the application reports an error, often a failed database login (find and fix the error).
- Does not respond on the port - the port is incorrect. After a test, the customer area shows which ports the container is actually listening on.
- The application responds encrypted - enable ‘Container speaks HTTPS’.
Connect your own domain
- In the Reachability tab, click Connect domain. Next to this, you’ll see how many custom domains your plan allows.
- Enter the domain, for example
www.muster.de, and save. - Create a DNS record with your domain provider. The exact entry is specified in the yellow note:
- a CNAME record pointing to the container’s platform address (
<container>-<projekt>.<basisdomain>) or - an A record pointing to the server address from the project header.
- a CNAME record pointing to the container’s platform address (
- Click Check DNS. If the entry is correct, the domain will be set up and the certificate issued automatically.
DNS changes can sometimes take a little time. We keep checking automatically - you don’t need to wait. If your domain is registered with us, you can change the record in the customer area (Edit DNS records).
CNAME or A record?
For subdomains such as www.muster.de we recommend the CNAME record: it automatically follows the platform address. For the domain without ‘www’ (muster.de), most providers do not allow a CNAME - in this case, use an A record pointing to the server address.
Access protection: who may access it?
Use Edit to specify who is allowed to access each web address:
- Everyone - public - anyone with the address can access the application.
- Certain IP addresses only - for example, your office or your VPN. Enter one IP address or a network per line, such as
203.0.113.0/24. - With password - a username and password are required before access is granted. The password must be between 10 and 72 characters long and is stored in encrypted form only.
- IP addresses and password - only from allowed networks and additionally with a password.
Custom TCP or UDP port
For services that do not require a browser, such as a game server or MQTT, click Open port. You specify the port within the container; the platform automatically assigns the public port. You will then see it in the Reachability tab; the service can be accessed via the server address and this port. Under Allowed sources, you can restrict access per port to specific IP addresses or networks - leaving this field blank means access is permitted from anywhere. The number of custom ports you can use depends on your plan.
Do not make databases public
Databases, caches and administration interfaces should never be accessible to the public. Connect them to your application via an internal network (networks and firewall) and protect administration interfaces at least with an IP allowlist or a password.