For websites and APIs, use HTTPS & domains instead: you get a stable https:// address with a certificate. For pod-to-pod traffic (an app talking to its database), use private networking: db.internal.
Public ports
svl run -d -p 80 -p 5432 -p 53/udp myimage
Each published port gets a high port on the node's public IPv4 and IPv6 addresses (the same number on both). svl run -d and svl inspect show them:
80/tcp → 157.20.113.121:30000, [2001:df3:80c0:998::79]:30000
Private ports
Add --private and nothing is exposed to the internet. Reach the port from your machine with a forward:
svl run -d -p 8888 --private jupyter/base-notebook
svl forward p-7k2xq9 8888 # → http://localhost:8888
svl forward p-7k2xq9 8888:9000 # → http://localhost:9000
Forwarding happens inside the pod, so services listening only on 127.0.0.1 work too. You can forward any port, published or not.
Outbound
Pods can reach the internet over IPv4 and IPv6, and use public DNS. They can't reach other pods, the node they run on, or private address ranges.