## Render Private Services

Render private services are just like web services, with one exception: **private services aren't reachable via the public internet.** They _do not_ receive an `onrender.com` subdomain:

|              | External clients (browsers, etc.) | Web service | Private service |
|--------------|-----------------------------------|-------------|----------------|
| Render       | ✅                                | ✅          | ❌             |

However, private services _are_ reachable by your other Render services on the same private network! This means they're perfect for services that only your own infrastructure needs to talk to.

Private services can listen on _almost_ any port ( [see details](/content/docs/private-network#port-restrictions/index.html)) and communicate using any protocol.

**Private services must bind to at least one port.**

If your service won't receive incoming traffic, instead create a background worker. See details [below](/content/docs/private-services#private-service-or-background-worker/index.html).

## Examples

Here are some deployment guides for tools that make great private services:

- [Deploy an Elasticsearch server](/content/docs/deploy-elasticsearch/index.html)
- [Deploy ClickHouse](/content/docs/deploy-clickhouse/index.html)

## Private service or background worker?

Like private services, your background workers are unreachable via the public internet. _Unlike_ private services, **background workers aren't even reachable via their private network:**

|              | Web service | Private service | Background worker |
|--------------|-------------|-----------------|-------------------|
| Render       | ✅          | ❌              | ❌                |

- If your internal service will bind to _at least one port_ and receive private network traffic, create a private service.
- Otherwise, create a background worker.

Background workers can _initiate_ network requests but can't _receive_ them. They usually perform long-running or resource-intensive tasks, which they fetch from a job queue that's often backed by a Render Key Value instance.

## Connect to your private service

See [Private Network](/content/docs/private-network#how-to-connect/index.html).

# Ready to help.

### Example prompts

- Add a custom domain
- Describe service types
- Restrict external access to database
- Set Node.js version
