Back to DocumentationPrivate Networking

Grouping servers and controlling device access

Decide which servers can reach each other, and which servers each of your devices can see.

June 19, 202626 views

Grouping servers and controlling device access

Private Networking gives you two independent controls, both free and managed from your dashboard.

Grouping servers

By default, your servers are segregated — each is reachable by your devices, but servers cannot reach each other. This is least-privilege and the safest default.

If you want servers to talk to each other (for clustering, shared databases, or hopping between boxes), put them in the same group. Servers in the same group can reach each other; servers in different groups stay isolated.

Controlling device access

For each of your devices you choose what it can reach:

  • All servers — the device reaches every server you have (simple "my laptop sees everything I own").
  • One group — e.g. a work laptop tied only to your "production" group.
  • A set of groups — e.g. an admin laptop allowed into "production" and "staging" but not "clients".

Both controls are free, take effect immediately, and never require re-installing anything. Change them anytime from the Private Networking page.

private-networkinggroupsaccess-controlsecurity