At least they're not as bad as Azure... :)
At least they're not as bad as Azure... :)
In Hetzner's specific case: they won't give me one or more additional /72s: only a /56 if I pay for it. Per server.
You can then just put an allow rule between arbitrary v6 addresses anywhere on the internet when you need connectivity without any other hacks like proxies, NAT, etc and the associated complexity and addressing ambiguity/context dependence of rfc1918 addresses.
So fex you can just curl or ssh to your mycontainer.mydomain.net or you can put an allow rule from mycontainer.mydomain.net to a vm or laptop on your home network.
Internetworking, they call it.
"Internal" is a context dependent term that you introduced. But to give a use case for that, for example you might want to have (maybe at a future date) two hosts on your networks on AWS and Hetzner talk to each other, still without allowing public connectivity.
If your containers have a Global Unicast Address then it's possible to look at connetion logs and figure out which container made a particular request, for instance.
Are you also afraid of port forwarding? Have you considered that your ISP could choose to send your router packets destined for RFC1918 addresses?