# Network

Source: https://docs.quake.ai/docs/network
Markdown: https://docs.quake.ai/docs/network.md
> Connect Quake AI workloads with isolated project networks, subnets, routers, floating IPs, and security group firewall rules.

---

# Network

Every workload on Quake AI needs a network path to other instances, to the internet, or both. The Network service gives you the building blocks: isolated project networks with subnets and DHCP, routers for inter-network traffic, floating IPs for public access, and security groups for per-port firewall rules.

[OpenStack Neutron](https://docs.openstack.org/neutron/latest/) backs Network. For details on how Quake AI implements OpenStack, see [How Quake AI uses OpenStack](/resources/migration/openstack).

## What you can do

<UseCaseGrid>
<UseCaseCard
  title="Create an isolated network"
  description="Set up a private network with subnets and DHCP for your project's instances to communicate securely."
  href="/docs/network/how-to/create-network"
  difficulty="beginner"
  estimatedTime="10 min"
  services={["Network"]}
/>
<UseCaseCard
  title="Expose a service to the internet"
  description="Allocate a floating IP and attach it to an instance so external traffic can reach your application."
  href="/docs/network/how-to/allocate-floating-ips"
  difficulty="beginner"
  estimatedTime="5 min"
  services={["Network", "Compute"]}
/>
<UseCaseCard
  title="Deploy a reverse proxy"
  description="Route requests to one or more application instances through software you operate."
  href="/resources/iac-templates/edge-reverse-proxy"
  difficulty="intermediate"
  estimatedTime="20 min"
  services={["Network", "Compute"]}
/>
<UseCaseCard
  title="Lock down traffic with security groups"
  description="Define firewall rules that control which ports and protocols can reach your instances."
  href="/docs/network/how-to/create-security-group"
  difficulty="beginner"
  estimatedTime="10 min"
  services={["Network"]}
/>
</UseCaseGrid>

## How it works

<Figure caption="Network topology: PublicEphemeral for quick testing vs. production path with private networks, routers, and floating IPs.">

```d2
direction: down

internet: Internet {shape: cloud}

quick: Quick Testing {
  net: PublicEphemeral
  vm: Instance
  net -> vm: direct attach
}

internet -> quick.net: public IP

production: Production {
  router: Router
  fip: Floating IP
  sg: Security Groups

  private: Private Network {
    web: Web Server
    app: App Server
    db: Database
  }

  fip -> sg -> private
  private.web -> private.app -> private.db
}

internet <-> production.router
production.router -> production.fip
```

</Figure>

A Quake AI project starts with two pre-built networks. **PublicEphemeral** lets you attach an instance directly for quick testing; the instance gets a public IP but is fully exposed. **PublicStatic** is the production path: your instances live on private networks you create, and you route external traffic through routers and floating IPs with security groups filtering every connection.

The typical pattern is: create a **network** and one or more **subnets** that define IP ranges and DHCP settings. Attach a **router** to connect your network to the external gateway. Allocate **floating IPs** and associate them with public instances. Apply **security groups** to control inbound and outbound traffic at the port level.

For applications that need traffic distribution or TLS termination, run a reverse proxy such as Caddy, Nginx, HAProxy, or Traefik on a Compute instance. A CDN or WAF can provide an external edge in front of that origin. For site-to-site connectivity, deploy a self-managed VPN gateway (WireGuard or IPsec) on a Compute instance; see the [Private Network + VPN template](/resources/iac-templates/private-network-vpn) for an OpenTofu configuration.

## Get started

To set up networking for a new project, start with [Create a network](/docs/network/how-to/create-network). If you already have instances running and need to expose them, see [Allocate floating IP addresses](/docs/network/how-to/allocate-floating-ips).

## Key concepts

<DocsSectionLinks section="network/concepts" grouping="concepts" primaryOnly />

## Security considerations

The platform provides network isolation between projects at the infrastructure level. You configure **security groups** to control traffic to and from your instances, **TLS** on application servers or reverse proxies, and **private networks** to keep internal traffic off the public internet. For a cross-service view of security topics, see [Security](/docs/security).

## Guides and reference

### Console guides

<ReferenceConsoleLinks service="network" />

### How-to guides

<DocsSectionLinks section="network/how-to" />

### CLI reference

<ReferenceServiceLinks service="network" group="cli" />

### API reference

<ReferenceServiceLinks service="network" group="api" />

## Related services

Compute instances are the primary consumers of network resources; every instance attaches to at least one network, and security groups can guard each one. See [Compute](/docs/compute). For encrypted object storage access over the network, see [Storage](/docs/platform#storage).
