Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Reachability & networks 5 min read

Making a container reachable on the web: address, SSL, your own domain and access protection

Initially, a container is only accessible within the project. It becomes reachable from outside via a reachability: as a web address via our central proxy with an SSL certificate, or as a dedicated TCP or UDP port for services that do not require a browser. You can configure both options when creating the container using the wizard, or later on the container’s page in the Reachability tab.

Setting up a web address with SSL

  1. Open the container and go to the Reachability tab.
  2. If the container has only been accessible internally so far, click Release anyway …; otherwise click Add reachability.
  3. Select Web (HTTPS) and enter the port in the container - the port on which the application in the container is listening; for WordPress, for example, this is 80.
  4. Only enable ‘Container speaks HTTPS’ if the application itself responds encrypted. Adjust the maximum upload size if necessary.
  5. Save.

Your address consists of the container name, project ID and base domain, for example wordpress-cms3oepx8.apps.pod01.speedit.solutions. We issue the SSL certificate automatically and renew it in good time.

The check chain

For each address, the check chain shows whether everything is working correctly right up to the application:

  • Address - the DNS record points to our server.
  • Certificate - valid and automatically renewed.
  • Container - running.
  • Application - responds on the port, for example with status 200.
Web address of a container with a check chain of the address, certificate, container and application
A web address has been set up: all four links of the check chain are green.

Click Test now to check the application again; the time of the last test is shown below. Typical results:

  • Responds with status 5xx - the address works, but the application reports an error, often a failed database login (find and fix the error).
  • Does not respond on the port - the port is incorrect. After a test, the customer area shows which ports the container is actually listening on.
  • The application responds encrypted - enable ‘Container speaks HTTPS’.

Connect your own domain

  1. In the Reachability tab, click Connect domain. Next to this, you’ll see how many custom domains your plan allows.
  2. Enter the domain, for example www.muster.de, and save.
  3. Create a DNS record with your domain provider. The exact entry is specified in the yellow note:
    • a CNAME record pointing to the container’s platform address (<container>-<projekt>.<basisdomain>) or
    • an A record pointing to the server address from the project header.
  4. Click Check DNS. If the entry is correct, the domain will be set up and the certificate issued automatically.
Your own domain with the status ‘Waiting for DNS’ and a note regarding the required CNAME or A record
Your own domain is waiting for the DNS record - the note specifies the exact destination.

DNS changes can sometimes take a little time. We keep checking automatically - you don’t need to wait. If your domain is registered with us, you can change the record in the customer area (Edit DNS records).

CNAME or A record?

For subdomains such as www.muster.de we recommend the CNAME record: it automatically follows the platform address. For the domain without ‘www’ (muster.de), most providers do not allow a CNAME - in this case, use an A record pointing to the server address.

Access protection: who may access it?

Use Edit to specify who is allowed to access each web address:

  • Everyone - public - anyone with the address can access the application.
  • Certain IP addresses only - for example, your office or your VPN. Enter one IP address or a network per line, such as 203.0.113.0/24.
  • With password - a username and password are required before access is granted. The password must be between 10 and 72 characters long and is stored in encrypted form only.
  • IP addresses and password - only from allowed networks and additionally with a password.
‘Edit reachability’ dialogue with the port, upload size and access protection options
Edit reachability: port, upload size and access protection using IP addresses and a password.

Custom TCP or UDP port

For services that do not require a browser, such as a game server or MQTT, click Open port. You specify the port within the container; the platform automatically assigns the public port. You will then see it in the Reachability tab; the service can be accessed via the server address and this port. Under Allowed sources, you can restrict access per port to specific IP addresses or networks - leaving this field blank means access is permitted from anywhere. The number of custom ports you can use depends on your plan.

Do not make databases public

Databases, caches and administration interfaces should never be accessible to the public. Connect them to your application via an internal network (networks and firewall) and protect administration interfaces at least with an IP allowlist or a password.

Which port in the container do I need to enter?
The port on which the application in the container is listening. This is specified in the image documentation and is usually found in the first few lines of the logs. Following a test, the customer area also displays the ports on which the container is listening.
Why can’t I get a certificate for my own domain?
The certificate will only be issued once the DNS record points to our server. Check the record with your domain provider and click on ‘Check DNS’.
How many domains and ports can I use?
That depends on your plan. Under ‘From outside’ in the ‘Network’ tab, you can see how many of your own ports and domains you are already using.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

gute Erreichbarkeit

sehr guter Service
Gerhard G.Recommends us · 08/07/2026

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.