SkillByAIOpen interactive version →

Lesson 18 / 25

Custom and Internal Networks

Separate tiers.

frontend and backend

Define custom networks to separate tiers: a frontend network for the proxy and the app, a backend network for the app and the database. A service on both networks bridges them; the proxy cannot reach the database directly. Marking a network internal: true blocks traffic to and from outside the host, which suits databases that never need internet access.

Network membership in a three-tier setup, run

I ran this with Docker Compose v2.38.1 and jq in the demo "shop" project. docker compose config parses, interpolates, merges and validates the files without starting containers; the Docker daemon was not running, so nothing was started. In the "nets" demo project the proxy is only on frontend, the database only on backend, and the app on both; the backend network is internal.

cd ../nets
docker compose config --format json | jq -c ".services | map_values(.networks | keys)"
docker compose config --format json | jq -c ".networks.backend.internal"

Output:

{"app":["backend","frontend"],"db":["backend"],"proxy":["frontend"]}
true

Isolate databases

Put databases on an internal backend network that only the services needing them join.

Quick check: In the demo, can the proxy reach the database directly?

  • No, they share no network
  • Yes, all services share one network
  • Only on port 80
  • Only if internal is true
Answer

No, they share no network — Shared networks define reachability.