{"id":5238,"plugin_id":"plugin_asdk_app_6a624c56bfe081918f7544f7d58f6faf","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T22:43:41.078Z","digest":"94555b4cd18154884379746fbe2fb13e2f9c2e01f793a8dae6c1f09da54249d1","against":null,"payload":{"name":"render-private-services","description":"Configures Render private services—internal-only apps that accept traffic exclusively from other Render services over the private network. Use when the user needs an internal API, microservice, gRPC server, sidecar, or any service that should not be publicly accessible. Also use when choosing between a private service and a background worker. Trigger terms: private service, pserv, internal service, internal API, microservice, gRPC, not public, private network service.","included_files":[{"relative_path":"references/patterns.md","size_in_bytes":3353}],"skill_md_contents":"---\nname: render-private-services\ndescription: >-\n  Configures Render private services—internal-only apps that accept traffic\n  exclusively from other Render services over the private network. Use when\n  the user needs an internal API, microservice, gRPC server, sidecar, or any\n  service that should not be publicly accessible. Also use when choosing\n  between a private service and a background worker.\n  Trigger terms: private service, pserv, internal service, internal API,\n  microservice, gRPC, not public, private network service.\nlicense: MIT\ncompatibility: Render private services (paid plans)\nmetadata:\n  author: Render\n  version: \"1.0.0\"\n  category: compute\n---\n\n# Render Private Services\n\nPrivate services are identical to web services except they have **no public URL**. They are reachable only by other Render services on the same **private network** (same region + workspace). Use them for internal APIs, microservices, gRPC servers, sidecar processes, and anything that should never face the internet.\n\n## When to Use\n\n- Building an **internal API** or **microservice** behind a public gateway\n- Running a **gRPC**, **TCP**, or other non-HTTP server that only your services call\n- Deploying infrastructure components (**Elasticsearch**, **ClickHouse**, **RabbitMQ**)\n- Choosing between a **private service** and a **background worker**\n\nFor public-facing HTTP services, use **render-web-services**. For services that don't receive any traffic, use **render-background-workers**.\n\n## Private Service vs Background Worker\n\n| Criterion | Private Service | Background Worker |\n|-----------|----------------|-------------------|\n| Binds to a port | **Yes** (required) | No |\n| Receives private network traffic | **Yes** | No |\n| Sends outbound traffic | Yes | Yes |\n| Has internal hostname | **Yes** | No |\n| Use case | Internal APIs, gRPC, TCP servers | Queue consumers, async processors |\n\n**Rule of thumb:** If the process **listens on a port** and other services call it, it's a private service. If it **pulls work from a queue** and never receives requests, it's a background worker.\n\n## How Private Services Work\n\n- No `onrender.com` subdomain—not reachable from the internet\n- Reachable at `<service-name>:<port>` on the private network by services in the same region and workspace\n- Can listen on **any port** (except restricted system ports)—not limited to HTTP or port 10000\n- Supports **any protocol**: HTTP, gRPC, TCP, WebSocket, custom binary protocols\n- Same build/deploy lifecycle as web services (build command, start command, pre-deploy, health checks via the private network)\n- Supports persistent disks, scaling, Docker runtime—same capabilities as web services\n\n## Connecting to a Private Service\n\nOther services reference a private service via its **internal hostname and port**:\n\n```\nhttp://<service-name>:<port>\n```\n\nIn Blueprints, wire the address using `fromService`:\n\n```yaml\n- key: INTERNAL_API_URL\n  fromService:\n    name: my-api\n    type: pserv\n    property: hostport\n```\n\nAvailable `fromService` properties for `pserv`:\n\n| Property | Value |\n|----------|-------|\n| `host` | Internal hostname (e.g. `my-api`) |\n| `port` | Port the service listens on |\n| `hostport` | `host:port` combined (e.g. `my-api:10000`) |\n\nYou can also reference a specific env var from the private service using `envVarKey` instead of `property`.\n\n## Port Binding\n\nPrivate services **must bind to at least one port**. If your process does not need to receive traffic, create a background worker instead.\n\n- Bind to `0.0.0.0` (not `127.0.0.1` or `localhost`)\n- The `PORT` env var defaults to `10000`, but you can listen on any non-restricted port\n- For non-HTTP protocols (gRPC, TCP), configure your server on the desired port and tell consumers the `hostport`\n\n## Blueprint Configuration\n\n```yaml\nservices:\n  - type: pserv\n    name: internal-api\n    runtime: node\n    region: oregon\n    plan: starter\n    buildCommand: npm ci && npm run build\n    startCommand: npm start\n    envVars:\n      - key: DATABASE_URL\n        fromDatabase:\n          name: db\n          property: connectionString\n```\n\n### Microservices pattern (gateway + internal services)\n\n```yaml\nservices:\n  - type: web\n    name: gateway\n    runtime: node\n    plan: starter\n    region: oregon\n    buildCommand: npm ci && npm run build\n    startCommand: npm start\n    envVars:\n      - key: USER_SERVICE_URL\n        fromService:\n          name: user-service\n          type: pserv\n          property: hostport\n      - key: BILLING_SERVICE_URL\n        fromService:\n          name: billing-service\n          type: pserv\n          property: hostport\n\n  - type: pserv\n    name: user-service\n    runtime: node\n    plan: starter\n    region: oregon\n    buildCommand: npm ci\n    startCommand: node server.js\n    envVars:\n      - key: DATABASE_URL\n        fromDatabase:\n          name: db\n          property: connectionString\n\n  - type: pserv\n    name: billing-service\n    runtime: python\n    plan: starter\n    region: oregon\n    buildCommand: pip install -r requirements.txt\n    startCommand: gunicorn billing:app\n    envVars:\n      - key: DATABASE_URL\n        fromDatabase:\n          name: db\n          property: connectionString\n```\n\n## References\n\n| Document | Contents |\n|----------|----------|\n| `references/patterns.md` | Microservice topology, gRPC setup, sidecar patterns, health checks for private services |\n\n## Related Skills\n\n- **render-web-services** — Public HTTP services\n- **render-networking** — Private network, DNS, service discovery\n- **render-background-workers** — Services that don't receive traffic\n- **render-blueprints** — Full `render.yaml` schema, `fromService` wiring\n- **render-scaling** — Instance types and autoscaling for private services\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}