Skip to documentation
Documentation menu · Public & private networking

Build & connect

Public & private networking

Use public access for external users and private connections between products in the same organization.

On this page

Public or private?

Public or private?
Public networkPrivate network
ScopeAccess over the internet through a service's public address.Internal connections between products in the same DLEZ organization.
When to useWebsite visitors, browser API requests, your laptop and external systems.App-to-MySQL/Redis, backend-to-backend or a VPS service in the same org.
AddressThe public URL/host and port shown for the service.The destination's private address/host and port in Console.
AuthenticationUse appropriate HTTPS/TLS, accounts and permissions.Passwords/tokens and permissions still apply. Private access does not replace authentication.

The rule: products in the same organization can connect privately

Flash Deploy, MySQL, Redis and VPS products in the same DLEZ organization can call one another using private addresses. The boundary is the organization, not an individual project.

Products in different projects within one org can communicate privately. Products in different orgs do not share a private network, even if you belong to both orgs. Signing in to Console does not make your laptop or browser part of the org's private network.

Create the products in the same org and use the destination's actual private endpoint. On a VPS, configure the service to listen on the appropriate interface and allow its port through the firewall. Org management permissions do not replace database or API permissions.

Why prefer private connections internally?

App-to-database, cache and service traffic uses the org's internal network without going through public endpoints. You do not need to expose a service publicly solely for another product in the org to call it. This reduces the endpoints you need to expose and separates internal traffic from user traffic.

Internal connections can use private endpoints independently of the website's public domain and DNS. Switching an app to a private endpoint does not automatically disable an existing public endpoint; check the service's access settings separately.

Private networking is not a promise of free bandwidth, fixed latency, automatic encryption of every connection or zero outages. Check your plan's limits and costs, authenticate requests and follow the service's TLS configuration.

Example: public app, private data

The browser calls the API over public HTTPS. Server-side API code uses private endpoints to call MySQL, Redis or a VPS in the same org. Frontend JavaScript running in a browser is an external client: do not put private hosts or database passwords in it.

Internet / browser
       | public HTTPS
       v
Your organization
  Flash Deploy (web + API)
    |-- private --> MySQL (source data)
    |-- private --> Redis (cache)
    `-- private --> VPS (custom service)

Switch an app to private networking

  1. Check that both the app and destination service belong to the same organization, not just similarly named projects.
  2. Open Connection or network information for the destination. Copy its actual private address and port; do not infer them from a public hostname.
  3. Update the server-side host/port variables or internal API URL your code reads. Keep the correct username, password, database and TLS settings.
  4. Apply the configuration and redeploy. Verify the effective host is private without printing passwords in logs.
  5. Test from the running app in the org: run SELECT 1, read/write a Redis key with a TTL or call a service health endpoint. Keep your website's public URL for users.

If a private connection fails

If a private connection fails
SymptomCheck
Laptop/browser cannot access a private hostThese are external clients. Test from the app in the org; use an authenticated public endpoint for external access.
Two products cannot connectCheck both orgs, the private host/port, service status and applied environment variables.
VPS connection refused or timeoutCheck the running process, listening interface and firewall for the required internal port.
Access denied or unauthorizedNetwork reachability does not grant data access. Check credentials, database name and API permissions.