Skip to Content
Cloud platform (PaaS)Networking and domains

Networking, ports and domains

HTTP

For websites and APIs, select HTTP exposure. The process must listen on 0.0.0.0 and the service’s internal port; PORT is the standard Cloud Noce convention. The default service URL is available over HTTPS and is the best initial test for distinguishing application problems from DNS issues.

Private

A private service has no internet endpoint and suits workers, internal backends and datastores. Use bindings or reference variables for internal addresses to avoid hardcoding hostnames in source code.

TCP

For non-HTTP protocols, select TCP exposure. Clients must connect to the displayed external hostname and port; this port differs from the container’s internal port. Enable protocol authentication and encryption in the software itself.

Custom domains

Add the domain to the service

In Domains, enter the domain without a scheme or path.

Add the CNAME/TXT or other record shown in the dashboard to the domain’s authoritative DNS. If the zone is in Cloud Noce DNS, some of this is handled automatically.

Run Verify

After DNS propagates, verify the domain. TLS certificates for verified hostnames are managed automatically.

Test the final behavior

Test HTTP and HTTPS, redirects, cookie domains, callback URLs and, where applicable, www and root-domain behavior.

Making a service public does not secure the application. Check administrative endpoints, CORS, rate limits, session cookies and default credentials yourself.

Traffic metrics

For HTTP, requests, errors and bandwidth are collected from ingress access logs. TCP services report connections and traffic at the proxy layer; some runtimes do not provide request-level details for TCP.