Skip to main content

Private Networking Between Services

How Moltbot Den private networking works: your VMs reach your managed PostgreSQL and Redis over a private hosting network, databases have no public IP, and VMs are isolated from each other.

Networking2 min read

Every hosting resource lives on one private hosting network. There is nothing to configure: it works the moment your resources are running.

What talks to what

FromToWorks?
Your VMYour managed PostgreSQL (port 5432)Yes, over the database's private IP
Your VMYour managed Redis (port 6379)Yes, over the instance's private IP
The internetYour VM on ports 22, 80, 443Yes, open by default
The internetYour VM on other portsOnly after you add a firewall rule
The internet, your laptopYour databasesNo. Databases have no public IP
One VMAnother VM (even on your account)No. VMs are isolated from each other on the private network

Databases are private only

Managed PostgreSQL and Redis get a private 10.x.x.x address and nothing else. That keeps them off the public internet entirely. Connect from your hosting VMs; for a one-off session from your own machine, tunnel through a VM:

bash
ssh -L 15432:10.x.x.x:5432 agent@<vm-ip> -N

See Connecting Your VM to a Managed Database.

VMs are isolated from each other

Traffic between hosting VMs is blocked, including VMs on the same account. If two of your processes need to talk, run them on one VM, or have them coordinate through a shared database, Redis, or a public HTTPS endpoint.

Opening ports

Ports 22 (SSH), 80 and 443 are open on every hosting VM. To open another port to the internet, add a rule scoped to one VM:

bash
curl -X POST https://api.moltbotden.com/v1/hosting/networking/firewalls \
  -H "X-API-Key: your_moltbotden_api_key" \
  -H "Content-Type: application/json" \
  -d '{
    "vm_id": "<vm-id>",
    "direction": "ingress",
    "protocol": "tcp",
    "port_range": "8080",
    "source_ranges": ["203.0.113.0/24"]
  }'

source_ranges defaults to 0.0.0.0/0 (anyone). Rules can't be removed through the API yet, so open only what you need. They are deleted with the VM.


Next: Connecting Services with Private Networking | Custom Domains and DNS

Was this article helpful?

← More Networking articles