Internal applications

Deploy private web apps without building a separate internal platform

Use the same Wodby stacks, environments, releases, backups, and operations as public applications, then put the complete app or selected web endpoints behind Cloudflare or Tailscale.

Private is an app setting

You do not need a special private Drupal, WordPress, Node.js, or OpenClaw stack. Application Access is selected for the app and applied to the eligible web endpoints it exposes.

  • Public remains the default.
  • Protection can cover the whole app or selected endpoints.
  • Provider resources follow the app lifecycle.

Use cases

Use familiar application stacks for private business workflows

Internal applications need the same delivery discipline as customer-facing products. Wodby keeps environments, updates, data operations, and access connected instead of treating the internal network as the complete platform.

Internal CMS and intranets

Run Drupal or WordPress as a private knowledge base, employee portal, publishing workflow, or operations site.

Admin tools and dashboards

Keep internal APIs, dashboards, admin interfaces, and support tools available only to approved users or devices.

Private previews and staging

Share customer previews and non-production environments without leaving an ordinary public application route exposed.

Private gateways and agents

Deploy OpenClaw and similar always-on gateways with stable private access instead of tying them to a developer laptop.

Access providers

Choose identity-protected publishing or a private device network

Both providers fit the same Application Access workflow. The difference is how users reach the app and which access system your organization already operates.

Compare access models

Workflow

Start with the app, then choose how it should be reached

Application Access is available during app creation and can be changed later from the app instance settings. Teams can discover the capability before deployment instead of rebuilding network access after the app is already public.

  1. 1

    Choose a ready Wodby stack or bring a custom application stack.

  2. 2

    Select Public or Protected access while creating the app.

  3. 3

    Protect the complete app or choose only the HTTP endpoints that should move behind the provider.

  4. 4

    Let Wodby deploy the workload, establish provider access, and keep both sides reconciled.

Deploy the internal app without creating another platform silo

Keep stacks, releases, environments, backups, and operations consistent with the rest of your applications while Cloudflare or Tailscale controls the user connection path.