Key idea
Inside a private network, services find each other by name, not by address, because addresses change whenever a server is replaced. An allowlist adds a second lock at the door: only connections from listed addresses get in.
Internal names
Your app could connect to its database at 10.0.2.20. It works until that server is replaced and comes back as 10.0.2.24, and then every app that hard-coded the old address breaks.
So private networks run their own DNS. The app connects to a name such as db.internal.example.com or just orders-db, and the network answers with whatever address that service has right now. Finding services this way is called service discovery.
These names only resolve inside the network. Look one up from your laptop and you get no answer, which is exactly right: outsiders shouldn't even learn what's there.
Allowlists
An IP allowlist is a list of source addresses allowed to connect. Everything else is refused before it can try a password. Ranges are written in CIDR notation:
203.0.113.7/32is one address.203.0.113.0/24is the 256 addresses from203.0.113.0to203.0.113.255.10.0.0.0/16is every address starting10.0..
The number after the slash says how many leading bits are fixed. Smaller numbers mean bigger ranges, so 0.0.0.0/0 means everyone.
Allowlists suit things that can't sit on a private network: an admin panel only your office uses, or a hosted database that your app servers reach from a known address.
What an allowlist can't do
- It isn't a login. Anyone behind an allowed address gets through, including everyone sharing your office's address. Keep passwords and TLS as well.
- It needs a fixed address. It matches where a connection comes from. If the connecting side's outbound address changes, as it does for many hosted platforms and home connections, no list can name it.
- It goes stale. Addresses get reassigned. Review the list, and remove entries nobody can explain.
Check yourself