Prompt
how to host internal tools in the cloud
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
A practical way to host internal tools in the cloud is to treat them like a small private web app platform with strong access control.
Common options
1) Private web app on a cloud VM
Best for: simple internal tools, fastest setup
- Run the app on an EC2 / Compute Engine / Azure VM.
- Put it behind a reverse proxy like Nginx.
- Restrict access with:
- VPN
- IP allowlists
- SSO via an identity-aware proxy
- Store secrets in a secrets manager.
Pros:
- Simple
- Cheap
- Easy to debug
Cons:
- You manage the server
- Less scalable
2) Containerized app on managed platform
Best for: teams that want easier deployment and scaling
Examples:
- AWS ECS / Fargate
- Google Cloud Run
- Azure Container Apps
- Kubernetes if you already use it
Pattern:
- Package the tool as a container
- Deploy to a private service
- Put it behind an internal load balancer or auth proxy
- Connect it to a private database
Pros:
- Less server management
- Better deployment workflow
- Scales well
Cons:
- Slightly more setup
- Networking/auth can be more complex
3) Fully managed internal app platform
Best for: enterprise environments
Examples:
- AWS App Runner + IAM/auth layer
- GCP IAP with Cloud Run
- Azure App Service with Entra ID
- Internal developer portals like Backstage
Use this if you want:
- SSO login
- Audit logs
- Easy role-based access
Recommended architecture
For most internal tools:
- Frontend app hosted on a cloud platform
- Backend API in same private network
- Database in a private subnet
- Authentication via SSO
- Access restricted by VPN or identity-aware proxy
- Logs/metrics enabled
- Secrets in a managed secrets store
Example flow:
- User signs in with Google Workspace / Okta / Azure AD
- Identity-aware proxy checks permissions
- User reaches the internal tool
- Tool calls internal API/database over private network only
Security checklist
- Use SSO, not shared passwords
- Enforce MFA
- Restrict access by role
- Put databases in private subnets
- Don’t expose admin tools to the public internet
- Use TLS everywhere
- Rotate secrets
- Enable audit logging
- Back up data regularly
Deployment workflow
A good basic pipeline:
- Code in GitHub/GitLab
- CI builds the app
- CI runs tests
- CI builds Docker image
- Push image to registry
- CD deploys to cloud environment
- Use Terraform/Pulumi for infrastructure
Simple decision guide
-
Need something quick and small?
Use a VM + VPN or IP allowlist. -
Need moderate scale and less ops?
Use Cloud Run / ECS / App Service with SSO. -
Need lots of internal apps and governance?
Use identity-aware proxy + private services + IaC.
Practical example
If you’re on Google Cloud:
- App hosted on Cloud Run
- Protected by Identity-Aware Proxy
- Auth via Google Workspace
- Database in Cloud SQL private IP
- Secrets in Secret Manager
- Infrastructure defined with Terraform
If you want, I can also give you:
- a reference architecture diagram,
- the cheapest setup,
- or a step-by-step guide for AWS, GCP, or Azure.