The Network tab of your project has three sections: who can access your containers from outside, which containers communicate with one another, and where your containers are permitted to establish connections.
01 · From outside
Here you can see all containers with their web addresses and ports, access protection settings and the status of your own domains, such as ‘Waiting for DNS’. Change takes you to the container’s reachability settings (Making a container reachable on the web). Below this, you’ll see how many custom ports and domains your plan allows.
02 · Between containers: networks
Every project has the network standard with internet access. Containers on the same network can be reached via their name, for example mariadb:3306. The platform assigns new internal IP addresses on every start - so always use the name.
To create your own network:
- Click on Create network. Next to this, you’ll see how many networks your plan allows.
- Enter a name, for example
datenbank. - Choose the internet access: Internal only or With internet.
- The subnet is optional - if you do not specify one, the platform will select one for you.
- Click on Create network.
Assigning a container to a network: open the container and, in the Settings tab under ‘Data, networks and start’, select the networks you want. Save - the container will be recreated in the process. A container can be part of several networks. A typical example is:
wordpressinstandard(with internet access, e.g. for updates) and indatenbankmariadbandvalkeyonly indatenbank(internal, without internet)
Without a network, a container cannot access other containers or the internet.
Databases belong on an internal network
An internal network has no connection to the internet. A database on that network is accessible only to containers on the same network and cannot establish connections to the outside world itself. This protects your data even if another part of your application is attacked.
03 · To the outside: outbound rules
Here you can specify where your containers are permitted to establish connections:
- Allow everything (default) - all destinations are permitted. You can block individual destinations using rules.
- Allowed destinations only - everything is blocked except the destinations you allow. This is the most secure setting if you know exactly which services your application requires.
A rule consists of a destination (IP address or network, for example 198.51.100.0/24), port (blank means all ports), protocol (TCP, UDP or All), action (Allow or Block) and a comment. Add rules using Add rule and click Save.
Fixed platform rules
Regardless of your own rules, the following fixed platform rules apply: no sending via port 25, no access to the platform’s internal networks, and no connection to other projects. Your applications send email via your provider’s mail server with authentication, usually via port 587 or 465.