# How to Create a VM on a Public Network

Source: https://docs.quake.ai/docs/compute/how-to/create-vm-public-network
Markdown: https://docs.quake.ai/docs/compute/how-to/create-vm-public-network.md

---

# How to create a VM on a public network

Create a virtual machine directly on the `PublicEphemeral` network for quick testing. The instance gets a public IP address automatically, so you can SSH in immediately.



Placing a virtual machine directly onto a public network is not recommended for production workloads. Use a [private network](/docs/compute/how-to/create-vm-private-network) with a floating IP for anything beyond quick tests.



<PrerequisiteBlock methods={["console", "cli", "api"]}>

- An [SSH key pair](/docs/tools/add-ssh-key) uploaded to your account
- A security group with SSH (port 22) allowed: create one in the steps below if needed

</PrerequisiteBlock>

## Step 1. Create a security group with SSH access

Skip this step if you already have a security group allowing SSH.

<MethodTabs>
<Method label="Console">

<NoMoreButton />

1. Select **Network** > **Security Groups** > **Create Security Group**.
2. Name it `quickStart` and select **OK**.
3. On the new group's row, open the **Settings** gear icon dropdown and select **Create Rule**.
4. Select **SSH** for the protocol (TCP port 22).
5. Select **OK** to add the rule.

</Method>
<Method label="CLI">

```bash
openstack security group create quickStart
openstack security group rule create \
  --protocol tcp --dst-port 22 --remote-ip 0.0.0.0/0 \
  quickStart
```

</Method>
<Method label="API">

```bash
curl -X POST "$OS_NETWORK_URL/v2.0/security-groups" \
  -H "X-Auth-Token: $OS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"security_group": {"name": "quickStart"}}'
```

Then add the SSH rule (see [create security group rules](/docs/network/how-to/create-security-group-rules) for the full API call).

</Method>
</MethodTabs>

## Step 2. Create the instance

<MethodTabs>
<Method label="Console">

1. Select **Compute** > **Instances** > **Create Instance**.
2. Name the instance (e.g., `quickstartvm`).
3. Select `us-east-1a` for the availability zone.
4. Select a flavor (e.g., `c2a.large` or `s1a.micro` for shared vCPUs).
5. Select **Ubuntu-22.04** for the image and set the disk to **10 GiB**. Check **Deleted with the instance**.
6. Select **Next: Network Config**.
7. Select the **Public Networks** tab, then select `PublicEphemeral`.
8. For subnets, select **Automatically Assigned Address**.
9. Select the `default` and `quickStart` security groups.
10. Select **Next: System Config**.
11. Select **Keypair** for the login type and choose your key pair.
12. Select **Next: Confirm Config** and confirm.

</Method>
<Method label="CLI">

```bash
openstack server create \
  --flavor c2a.large \
  --image Ubuntu-22.04 \
  --boot-from-volume 10 \
  --network PublicEphemeral \
  --key-name my-keypair \
  --security-group default \
  --security-group quickStart \
  quickstartvm
```

`--boot-from-volume 10` is required because all Quake AI flavors have `disk=0`. Without it the create returns HTTP 403 "Only volume-backed servers are allowed for flavors with zero disk".

Wait for the instance to become active:

```bash
openstack server show quickstartvm -c status -c addresses
```

</Method>
<Method label="API">

```bash
curl -X POST "$OS_COMPUTE_URL/servers" \
  -H "X-Auth-Token: $OS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "server": {
      "name": "quickstartvm",
      "flavorRef": "FLAVOR_ID",
      "imageRef": "IMAGE_ID",
      "networks": [{"uuid": "PUBLIC_EPHEMERAL_NETWORK_ID"}],
      "key_name": "my-keypair",
      "security_groups": [
        {"name": "default"},
        {"name": "quickStart"}
      ]
    }
  }'
```

</Method>
</MethodTabs>



The Console delete-instance dialog has no option to delete attached volumes. The **Deleted with the instance** checkbox you set when creating the instance controls whether the platform removes the boot volume; the delete dialog does not. Boot volumes created by the instance wizard show no name in **Storage** > **Volumes** (the Name column renders `-`), so the Console cannot match a leftover boot volume by name. Identify it by its **Available** status and creation time, or read the volume ID from the CLI or API.



## Step 3. Connect to the instance

Once the instance is active, SSH in using the assigned public IP:

```bash
ssh ubuntu@INSTANCE_IP_ADDRESS
```

Type `yes` to accept the host key. Your prompt changes to `ubuntu@quickstartvm`.

## Step 4. View instance details

<MethodTabs>
<Method label="Console">

Select **Compute** > **Instances**, then select your instance. The detail view exposes eight tabs:

- **Detail**: configuration, flavor, security groups, key pairs
- **Volumes**: the boot volume and any attached volumes
- **Instance Snapshots**: snapshots taken from this instance
- **Interfaces**: the ports connecting the VM to one or more networks
- **Floating IPs**: any floating IPs associated with the instance
- **Security Groups**: applied groups
- **Action Logs**: console actions (create, reboot, attach volume, etc.)
- **Console Log**: recent serial console output, useful for boot debugging

</Method>
<Method label="CLI">

```bash
openstack server show quickstartvm
```

</Method>
<Method label="API">

```bash
curl -s "$OS_COMPUTE_URL/servers/SERVER_ID" \
  -H "X-Auth-Token: $OS_TOKEN" | python3 -m json.tool
```

</Method>
</MethodTabs>

## See also

- [How to point a domain at a Quake AI resource](/docs/network/how-to/point-domain-to-quake-ai)
- [Compute API Reference](/reference/compute): full parameter documentation for the Compute API
- [How to create a VM on a private network](/docs/compute/how-to/create-vm-private-network) (recommended for production)
- [How to create an instance](/docs/compute/how-to/create-instance) (full reference)
- [Instances CLI reference](/reference/compute/instances-cli)
- [Instances API reference](/reference/compute/instances-api)
- [Compute console](/reference/compute/console/index)
