Render Networking

作者 render-osse8f889396634MIT收錄於 2026年10月8日更新於 2026年10月8日

Connects Render services over the private network—internal DNS, service discovery, and cross-service communication. Use when the user needs to wire services together, resolve internal hostnames, troubleshoot connectivity between services, configure environment isolation, or understand which services can reach each other.

僅含說明DevOps & Cloud
AI 產生的概覽

說明 Render 私有網路:內部 DNS、服務探索、連接埠以及服務間連線能力。

功能
此技能提供 Render 私有網路的指引,涵蓋哪些資源可以傳送或接收私有流量、內部主機名稱與 URL、多執行個體服務的探索 DNS、連接埠規則、環境隔離以及 AWS PrivateLink。它也指向兩份參考文件,分別說明架構模式與疑難排解步驟。產出的是說明與設定指引,而非檔案或程式碼。
適用情境
適用於將 Render 服務彼此串接、解析內部主機名稱、排解服務間連線問題,或確認哪些服務可以互相存取時。也適合關於連接埠限制、免費方案私有流量、環境隔離或 PrivateLink 的問題。
執行需求
不需要指令碼或工具,僅為說明性內容。前提是了解位於相同區域與相同工作區的 Render 服務;隨附的兩份參考文件由模型讀取。

Render private networking

Render’s private network lets services talk to each other without exposing traffic on the public internet. Use this skill when users need internal connectivity, discovery across scaled instances, or correct URL/port behavior for Blueprints and the Dashboard.

When to Use This Skill

  • Designing or debugging service-to-service traffic on Render
  • Questions about internal hostnames, internal URLs, or Connect > Internal in the Dashboard
  • Service discovery across multiple instances (custom load balancing, mesh-style setups)
  • Port limits, reserved ports, or multi-port web services (public vs private)
  • Free-tier web services and who can send vs receive private traffic
  • Environment isolation (Professional+) or AWS PrivateLink for private egress/ingress patterns

For step-by-step architecture examples and Blueprint patterns, see references/communication-patterns.md. For failure modes and fixes, see references/troubleshooting.md.

Private Network Basics

Private connectivity is available only when all of the following hold:

  • Services are in the same region
  • Services are in the same workspace

If either differs, private DNS and internal routing will not connect those services.

Who can communicate

ResourcePrivate inboundPrivate outboundInternal hostname
Web ServiceYes (paid tiers; see Free tier below)YesYes
Private ServiceYesYesYes
Background WorkerNoYesNo
Cron JobNoYesNo
Workflow RunNoYesNo
Static Site——Not on private network
Managed PostgresVia internal URL (from allowed clients)N/A (datastore)Via internal URL
Key ValueVia internal URL (from allowed clients)N/A (datastore)Via internal URL

Free-tier Web Services: They may send private traffic to other services, but they cannot receive inbound private traffic. Plan upgrades or topology changes apply if a free web service must accept private connections.

Workers, crons, and workflow runs initiate outbound connections (e.g., to internal URLs or private service hostnames) but are not reachable by internal hostname for inbound calls.

Internal Addresses

  • Open the service in the Render Dashboard → Connect → Internal tab for the canonical internal hostname, URL, and connection details.
  • Clients often need an explicit scheme in code or config, e.g. http://service-name:port or https://... when TLS applies—do not assume a bare hostname alone is enough for every HTTP client.
  • URL shape: http://[internal-hostname]:[port]/path (adjust scheme/port per service).

Service Discovery

For services with multiple instances, Render exposes a discovery DNS name that resolves to all instance IPs for that service. The pattern is [hostname]-discovery (see Dashboard docs for the exact hostname shown for your service).

  • RENDER_DISCOVERY_SERVICE is set in environments where discovery applies; use it with the discovery hostname pattern for scripts and app code that need instance lists.
  • Use case: Custom load balancing, health aggregation, or any logic that must fan out or pick among instances explicitly instead of a single internal hostname.

See references/communication-patterns.md for discovery-oriented patterns.

Port Rules

  • Maximum 75 open ports per service.
  • Reserved ports (do not bind your app to these for normal use): 10000 (public HTTP proxy path), 18012, 18013, 19099.
  • Multi-port Web Services: Only one port receives public HTTP traffic; that port must align with the PORT environment variable. Additional ports are for private network access only.

When something fails to connect, verify the target is listening on the expected port and that the port is not reserved or blocked by misconfiguration.

Environment Isolation

On Professional and higher workspaces, you can configure per-environment rules so private traffic does not cross certain environment boundaries. If private calls work in one environment but not another, check workspace environment isolation settings before assuming DNS or app bugs.

AWS PrivateLink

Professional+ workspaces can use AWS PrivateLink to extend private connectivity to or from external AWS VPCs and approved endpoints. This is separate from default service-to-service private DNS; use it when the architecture requires private access to Render or from Render to specific AWS resources without the public internet.

Common Patterns

Short summaries; full diagrams and Blueprint notes live in references/communication-patterns.md.

  1. Web gateway + private backends — Public Web Service terminates HTTP; internal calls use private hostnames and ports to Private Services or internal URLs.
  2. Worker to database — Background Worker (no internal hostname) connects outbound to Postgres or Key Value internal URLs.
  3. Microservices — Private Services (and eligible Web Services) call each other by internal hostname:port on the private network.

References

DocumentPurpose
references/communication-patterns.mdGateway, worker→DB, mesh, URL construction, Blueprint fromService, discovery load balancing, private health checks
references/troubleshooting.mdDNS, ports, region/workspace, free tier, protocol, resolver, environment isolation

Related Skills

  • render-web-services — Public web services, PORT, and HTTP behavior
  • render-private-services (planned) — Private Service–specific setup and scaling
  • render-blueprints — render.yaml, fromService, and multi-service wiring

來源與署名

來源:render-oss/render-plugin-claude-code位於skills/render-networking提交e8f8893

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架