Learning paths / Cloud foundations / Load balancers and private networks

Internal names and allowlists

Reading · 5 min · Module 8, lesson 3 of 410 min left in this module

Module 8 · Load balancers and private networksLesson 3 of 4

Goal: Explain why services find each other by internal names, and what an IP allowlist can and can't protect.

Key idea

Inside a private network, services find each other by name, not by address, because addresses change whenever a server is replaced. An allowlist adds a second lock at the door: only connections from listed addresses get in.

Internal names

Your app could connect to its database at 10.0.2.20. It works until that server is replaced and comes back as 10.0.2.24, and then every app that hard-coded the old address breaks.

So private networks run their own DNS. The app connects to a name such as db.internal.example.com or just orders-db, and the network answers with whatever address that service has right now. Finding services this way is called service discovery.

These names only resolve inside the network. Look one up from your laptop and you get no answer, which is exactly right: outsiders shouldn't even learn what's there.

Allowlists

An IP allowlist is a list of source addresses allowed to connect. Everything else is refused before it can try a password. Ranges are written in CIDR notation:

  • 203.0.113.7/32 is one address.
  • 203.0.113.0/24 is the 256 addresses from 203.0.113.0 to 203.0.113.255.
  • 10.0.0.0/16 is every address starting 10.0..

The number after the slash says how many leading bits are fixed. Smaller numbers mean bigger ranges, so 0.0.0.0/0 means everyone.

Allowlists suit things that can't sit on a private network: an admin panel only your office uses, or a hosted database that your app servers reach from a known address.

What an allowlist can't do

  • It isn't a login. Anyone behind an allowed address gets through, including everyone sharing your office's address. Keep passwords and TLS as well.
  • It needs a fixed address. It matches where a connection comes from. If the connecting side's outbound address changes, as it does for many hosted platforms and home connections, no list can name it.
  • It goes stale. Addresses get reassigned. Review the list, and remove entries nobody can explain.

Check yourself

Your app connects to its cache at 10.0.3.15. After maintenance the cache comes back at 10.0.3.40 and the app fails. What prevents this next time?
Which range covers exactly the addresses 198.51.100.0 to 198.51.100.255?

In the docs