Amazon's private network is private by default, I believe Google's is as well, and I believe Azure's is. Digital Ocean is acting much more like a traditional VPS company than a modern cloud computing company here.
Granted we're probably now distinguishing between being able to see unencrypted traffic and being able to access ports on a machine. They're both bad, but I'd argue having your DB port exposed to the world is probably worse.
But, in that is a deeper truth: a VPS is a cheaper machine. It becomes "cloud" when you use many machines together. If you're using many machines, you really want intercommunication between those machines to be easy, fast and - yes - reasonably secure.