Key idea
Give a public address only to what visitors must reach: usually the load balancer, on ports 443 and 80. Everything else, including app servers and above all the database, belongs on a private network, where the internet has no way in.
Private addresses
Three ranges of IPv4 addresses are reserved for private networks:
10.0.0.0to10.255.255.255172.16.0.0to172.31.255.255192.168.0.0to192.168.255.255
Routers on the internet don't carry traffic to these addresses, so nobody outside can connect to 10.0.2.20 directly. Your home router uses the same trick: your laptop is probably on 192.168.x.x, and one public address stands for the whole house.
Servers on a private network can still reach out, for example to call a payment API or download updates. Outbound connections work; nothing unrequested gets in.
Why the database stays private
Anything with a public address gets probed within minutes of appearing. Automated scanners sweep the whole internet for open database ports, such as 5432 for PostgreSQL, 3306 for MySQL and 6379 for Redis, then try default passwords and known bugs.
A private database removes that risk entirely: to reach it, an attacker must first break into one of your servers. Leaked databases often weren't hacked in any clever way; they were simply open, sometimes with no password at all.
Deciding, part by part
Ask of each part: does a visitor's browser need to connect to it?
- Load balancer: yes. Public, ports 443 and 80.
- App servers: no. Only the load balancer talks to them.
- Internal services and workers: no. Other servers call them.
- Database and cache: no. Only your app servers connect.
A firewall enforces these choices: it lists which connections may come in, and blocks everything else by default.
If it has to be public
Some hosted database providers give you only a public endpoint, or your app runs somewhere that can't join the database's private network. Then lock it down: require TLS, use a long random password for that one database user, and limit which addresses may connect where you can (next lesson). Never leave the default user or password in place.
Check yourself