# Migrate from GCP Compute Engine to Quake AI compute

Source: https://docs.quake.ai/docs/compute/migration/migrate-from-gce
Markdown: https://docs.quake.ai/docs/compute/migration/migrate-from-gce.md

---

# Migrate from GCP compute engine to Quake AI compute

You use this guide to move compute workloads from GCP Compute Engine to Quake AI (OpenStack Nova). GCP can export custom images to QCOW2, OpenStack Glance's preferred format, with Cloud Build handling the conversion internally so you skip the manual `qemu-img` step. For most workloads, rebuild and rsync stays faster, but you can use image export for custom GCE images with extensive baked-in configuration.

## Service mapping

<MigrationTable provider="gcp" service="compute" />


## Prerequisites

- A Quake AI account with [application credentials](/docs/tools/generate-app-credentials)
- The [OpenStack CLI](/docs/tools/install-openstack-client) installed and configured
- SSH access to your GCE instances
- An SSH key pair imported to Quake AI (`openstack keypair create --public-key`)
- For image export: `gcloud` CLI installed and Cloud Build API enabled

## Image portability

GCP supports exporting custom images to QCOW2. The export pipeline, powered by Cloud Build, handles the format conversion internally, so you do not run a separate `qemu-img` step. Among major providers, GCP is the one whose export command produces QCOW2 output directly.

```bash
# Export directly to QCOW2
gcloud compute images export \
  --image MY_CUSTOM_IMAGE \
  --destination-uri gs://MY_BUCKET/MY_IMAGE_QCOW2 \
  --export-format qcow2

# Download from Cloud Storage
gsutil cp gs://MY_BUCKET/MY_IMAGE_QCOW2 .

# Upload to Glance
openstack image create MY_IMAGE_NAME \
  --disk-format qcow2 --container-format bare \
  --file ./MY_IMAGE_QCOW2
```



You can export only user-created or imported images. You cannot export Google-provided public images (Ubuntu, Debian, and similar); use Quake AI's public images instead. Export uses Cloud Build under the hood, so the Cloud Build API must be enabled. The Compute Engine service account needs `roles/compute.storageAdmin`, `roles/storage.objectAdmin`, and `roles/storage.admin`. If the default Compute Engine service account is disabled, create a custom service account with those roles.



**When to use image export:** Use QCOW2 export for custom images with extensive baked-in software or configuration. For standard OS images, use Quake AI public images and rebuild.

## Flavor mapping

GCP machine type families map to Quake AI flavor families by their RAM-to-vCPU ratio. Standard (4:1) maps to m2a, highmem (8:1) maps to r2a, and highcpu (1:1) maps closest to c2a (though Quake AI c2a provides 2 GiB RAM per vCPU, more than GCP highcpu).

| GCP Machine Type | vCPUs | RAM (GiB) | Quake AI Flavor | vCPUs | RAM (GiB) | Notes |
|---|---|---|---|---|---|---|
| e2-micro | 2 (shared) | 1 | s1a.micro | 1 | 1 | Shared → shared; fewer vCPUs on Quake AI |
| e2-small | 2 (shared) | 2 | s1a.small | 1 | 2 | Shared → shared |
| e2-medium | 2 (shared) | 4 | s1a.medium | 2 | 4 | Close match |
| e2-standard-4 | 4 | 16 | m2a.xlarge | 4 | 16 | Exact ratio match |
| e2-standard-8 | 8 | 32 | m2a.2xlarge | 8 | 32 | Exact ratio match |
| n2-standard-2 | 2 | 8 | m2a.large | 2 | 8 | Exact ratio match |
| n2-standard-8 | 8 | 32 | m2a.2xlarge | 8 | 32 | Exact ratio match |
| n2-standard-32 | 32 | 128 | m2a.8xlarge | 32 | 128 | Exact ratio match |
| n2-highcpu-4 | 4 | 4 | c2a.xlarge | 4 | 8 | Quake AI provides 2x the RAM |
| n2-highcpu-8 | 8 | 8 | c2a.2xlarge | 8 | 16 | Quake AI provides 2x the RAM |
| n2-highmem-2 | 2 | 16 | r2a.large | 2 | 16 | Exact ratio match |
| n2-highmem-8 | 8 | 64 | r2a.2xlarge | 8 | 64 | Exact ratio match |
| c2-standard-8 | 8 | 32 | m2a.2xlarge | 8 | 32 | Exact ratio match |

GCP highcpu (1:1 ratio) is tighter than Quake AI c2a (2:1 ratio). If your workload is CPU-bound with minimal memory, c2a still fits; you get more RAM per vCPU on Quake AI, which adds headroom.

GCP also offers newer machine series (N4, C3, C3D, C4) with similar RAM-to-vCPU ratios. Apply the same ratio-based mapping: standard series (4:1) maps to m2a, highcpu series (1:1) maps to c2a, and highmem series (8:1) maps to r2a.

## Migration approach

### Option 1: Containerized workloads (recommended)

If your GCE instances run containers (or you use GKE), migrate container images and redeploy.

1. Push container images from Artifact Registry to a portable registry. Google Container Registry (`gcr.io`) was shut down in March 2025; Artifact Registry (`pkg.dev`) is the current GCP container registry:

```bash
# Pull from Artifact Registry (current GCP registry)
docker pull REGION-docker.pkg.dev/MY_PROJECT/MY_REPOSITORY/MY_APP:latest
docker tag REGION-docker.pkg.dev/MY_PROJECT/MY_REPOSITORY/MY_APP:latest \
  MY_REGISTRY/MY_APP:latest
docker push MY_REGISTRY/MY_APP:latest
```

2. Provision a Nova instance on Quake AI:

```bash
openstack server create \
  --image "Ubuntu-22.04" \
  --flavor m2a.xlarge \
  --network MY_NETWORK \
  --key-name MY_KEY \
  --security-group MY_SECURITY_GROUP \
  MY_INSTANCE_NAME
```

3. Install Docker and deploy:

```bash
ssh ubuntu@FLOATING_IP
sudo apt update && sudo apt install -y docker.io
sudo docker pull MY_REGISTRY/MY_APP:latest
sudo docker run -d -p 80:8080 MY_REGISTRY/MY_APP:latest
```

### Option 2: Rebuild and rsync (non-containerized)

1. Provision a Nova instance with the same base OS:

```bash
openstack server create \
  --image "Ubuntu-22.04" \
  --flavor m2a.xlarge \
  --network MY_NETWORK \
  --key-name MY_KEY \
  --security-group MY_SECURITY_GROUP \
  MY_INSTANCE_NAME
```

2. Assign a floating IP:

```bash
openstack floating ip create PublicStatic
openstack server add floating ip MY_INSTANCE_NAME FLOATING_IP
```

3. Install your application stack on the Quake AI instance. Reuse cloud-init configs, Ansible playbooks, or startup scripts.

4. Transfer application data from the GCE instance:

```bash
rsync -avz --progress -e "ssh -i ~/.ssh/MY_KEY" \
  MY_USER@GCE_EXTERNAL_IP:/path/to/app/data \
  ubuntu@FLOATING_IP:/path/to/app/data
```

5. Migrate databases:

```bash
# PostgreSQL
pg_dump -h GCE_EXTERNAL_IP -U MY_USER MY_DATABASE | \
  psql -h FLOATING_IP -U MY_USER MY_DATABASE

# MySQL
mysqldump -h GCE_EXTERNAL_IP -u MY_USER -p MY_DATABASE | \
  mysql -h FLOATING_IP -u MY_USER -p MY_DATABASE
```



GCP bills egress per GB across two network service tiers. Premium Tier, the default, runs steeper than AWS for migration-sized transfers, while Standard Tier provides a monthly free allowance and lower per-GB rates that are comparable to AWS for large transfers. For large data exports, Standard Tier is often the cost-effective path. Confirm current rates on the [GCP network pricing page](https://cloud.google.com/vpc/network-pricing).



## Key pair and security setup

### Import your SSH key

If you already use an SSH key pair with GCE, import the public key to Quake AI:

```bash
openstack keypair create --public-key ~/.ssh/id_ed25519.pub MY_KEY
```

Or generate a new key pair:

```bash
openstack keypair create MY_KEY > MY_KEY.pem
chmod 600 MY_KEY.pem
```

### Translate GCP firewall rules to security groups

GCP firewall rules support both allow and deny with priority ordering. Neutron security groups are allow-only and additive. If your security posture relies on deny rules, rethink the logic for an additive model where you allow only what is needed.

```bash
openstack security group create web-tier
openstack security group rule create web-tier \
  --protocol tcp --dst-port 22 --remote-ip 0.0.0.0/0
openstack security group rule create web-tier \
  --protocol tcp --dst-port 80 --remote-ip 0.0.0.0/0
openstack security group rule create web-tier \
  --protocol tcp --dst-port 443 --remote-ip 0.0.0.0/0
```



GCP firewall rules can target instances by network tags. Neutron security groups target by port binding (per instance). If you used tag-based targeting, apply the equivalent security group to each Quake AI instance individually. See the [network migration guide](/docs/network/migration/migrate-from-gcp-vpc) for full firewall rule translation.



## Validation checklist

After migrating each workload, verify:

- [ ] Application responds correctly on the Quake AI instance
- [ ] All expected ports are accessible through the security group
- [ ] Data integrity: compare file checksums or row counts between source and destination
- [ ] Database connectivity from the application to any migrated databases
- [ ] DNS records updated to point to the new Quake AI floating IP
- [ ] Monitoring in place (self-managed Prometheus + Grafana to replace GCP Monitoring)
- [ ] cloud-init or startup scripts run cleanly on the new instance
- [ ] SSL/TLS certificates installed and renewed

## Provider-specific gotchas

| Topic | Detail |
|---|---|
| Egress costs | GCP bills egress per GB. Premium Tier runs steeper than AWS; Standard Tier is comparable for large transfers. See [GCP network pricing](https://cloud.google.com/vpc/network-pricing). |
| Committed Use Discounts | Check for active CUDs before decommissioning. CUDs cannot be cancelled; you pay for the full commitment term (1 or 3 years) regardless of usage. Sustained Use Discounts (SUDs) are automatic and do not create a commitment, so you can decommission at any time without penalty. |
| Service accounts | GCP service accounts with workload identity have no Quake AI equivalent. Switch to [OpenStack application credentials](/docs/tools/generate-app-credentials). |
| GKE workloads | GKE → self-managed K8s is the most complex migration. See the [Kubernetes migration guide](/docs/kubernetes/migration/migrate-from-gke). |
| Firewall deny rules | GCP supports deny rules with priority. Neutron is allow-only. Rethink deny-based postures. |
| QCOW2 image export | On GCP you export custom images as QCOW2 without a manual `qemu-img` step; Cloud Build converts internally. |
| Custom machine types | GCP supports arbitrary vCPU/RAM ratios via custom machine types. Apply the ratio-based Quake AI flavor selection: calculate GiB per vCPU and select the family (m2a for 4:1, r2a for 8:1, c2a for 2:1, s1a for shared). |

## See also

- [Migrating from GCP to Quake AI](/resources/migration/from-gcp): full cross-service migration hub
- [Coming from GCP](/resources/migration/coming-from-gcp): concept translation reference
- [Create an instance](/docs/compute/how-to/create-instance): full instance provisioning workflow
- [Compute migration guides](/docs/compute/migration): all provider guides
