VPC on Quake AI
Coming from another cloud?
▸AWS·Amazon Virtual Private Cloud
Amazon Virtual Private Cloud
- AWS VPC is regional with CIDR /16-/28.
- OpenStack Networks project-scoped L2 with flexible CIDR.
- AWS requires IGW for public.
- OpenStack provider nets or floating IPs.
▸Azure·Virtual Network (VNet)
Virtual Network (VNet)
- Azure VNets are strictly regional Layer 3 overlays scoped to one subscription with no L2 VLAN support ().
- VNets and subnets creation free, but subnets min /29 with Azure reserving 5 IPs per subnet ().
- Managed via ARM REST APIs/PowerShell/CLI vs Neutron REST API.
- Isolated per subscription; peering for cross-VNet connectivity vs OpenStack project networks connected via routers.
▸DigitalOcean·VPC (VPC Network)
VPC (VPC Network)
- Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
- Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
- NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
- Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
▸Google Cloud·VPC Network
VPC Network
- GCP VPC is global (spans all regions) whereas OpenStack Neutron networks are project-scoped and region-local.
- GCP uses shared VPC for cross-project networking (requires org-level config); OpenStack uses shared networks via admin.
- Subnets in GCP are regional, auto-mode creates one per region automatically; OpenStack requires explicit subnet creation.
- GCP VPC Flow Logs per-subnet; OpenStack has no native equivalent without external tools.
▸Hetzner·Networks
Networks
- Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs.
- CCM supports route controller for pod networking when enabled; no native provider networks like OpenStack.
- Limited to Hetzner regions, IPv4 only for private (IPv6 public).
- Networks are free with no usage charges, unlike potential metering in OpenStack clouds ().
VPC on Quake AI
Quake AI does not expose a single object named VPC or virtual private cloud. The same job is done with networks (including subnets as IP ranges inside a network), routers (routing and NAT between segments), and floating IPs (stable public addresses on private instances).
If you are used to AWS VPC, Azure VNet, or GCP VPC networks, map that mental model to these Neutron primitives inside a project.
How the pieces map#
| VPC habit | On Quake AI |
|---|---|
| One isolated network per environment | Create a private network per tier or environment |
| Subnets in availability zones | Subnets with CIDR blocks on that network |
| Internet gateway + route tables | Router attached to PublicStatic plus static routes |
| Elastic IP on a private instance | Floating IP associated to the instance port |
| Security group / NACL | Security groups on ports (stateful rules) |
Each project scopes networks by default. Instances on the same private network reach each other at Layer 2; routers provide north-south paths and NAT.
On Quake AI#
Built-in external networks include PublicEphemeral (direct provider attachment for quick tests) and PublicStatic (routed access through a router). Production layouts typically use a private network, a router, and floating IPs rather than attaching workloads directly to a public provider network.
What other providers call this#
| Provider | Their term | Quake AI mapping |
|---|---|---|
| AWS | VPC | Networks + subnets + routers |
| Azure | Virtual network (VNet) | Networks + subnets + routers |
| Google Cloud | VPC network | Networks + subnets + routers |
| DigitalOcean | VPC | Networks + subnets (region-scoped attachment rules differ) |
| Hetzner | Network | Private networks attached to servers |
What to read next#
- Networks: private segments, built-in external networks, and topology
- Build a private network with two VMs: hands-on VPC-shaped layout
- Migrate from an AWS VPC: subnet and routing cutover patterns
Related content
Pages
How-tos
How to allocate floating IP addresses
Network
How to auto-scale a VM tier with Heat
Automation
How to connect to a database on a private network
Databases
How to Create a Cluster Template
Kubernetes
How to Create a Kubernetes Cluster
Kubernetes
How to Create a Network
Network
How to Create a Router
Network
How to Create a Virtual Machine Instance
Compute
How to Create a VM on a Private Network
Compute
How to Create a VM on a Public Network
Compute
How to deploy a multi-tier application with Terraform
Automation
How to deploy VMs with Terraform (simple example)
Automation
How to front a Quake AI workload with a web application firewall
Network
How to harden a Quake AI virtual machine
Compute
How to host a static site on object storage
Object storage
How to point a domain at a Quake AI resource
Network
How to provision a production-ready VM
Compute
How to put a CDN in front of a Quake AI workload
Network
How to run blue/green or canary deployments on Quake AI
Network
How to self-host authoritative DNS on Quake AI
Network
How to Send Transactional Email from a Quake AI Workload
Cross-cutting
How to set up a site-to-site or remote-access VPN to Quake AI
Network
How to set up SSH bastion access into a private subnet
Network
Tutorials
Explanations
Reference
API Endpoints
Tools
Cluster templates console
Kubernetes
Flavors Console
Compute
Floating IPs Console
Network
Network Console
Network
Network Service API Reference
Network
Network Service CLI Reference
Network
Networks Console
Network
Ports API Reference
Network
Ports Console
Network
Routers API Reference
Network
Routers CLI Reference
Network
Routers Console
Network
Security Groups Console
Network
Topology Console
Network
Overviews
migration
How Quake AI uses OpenStack
Platform
Migrate a B2B SaaS application to Quake AI
Automation
Migrate a web application to Quake AI
Automation
Migrate from AWS VPC to Quake AI
Network
Migrate from Azure VNet to Quake AI
Network
Migrate from DigitalOcean VPC to Quake AI
Network
Migrate from GCP VPC to Quake AI
Network
Migrate from Hetzner Cloud Networks to Quake AI
Network
Migrate from Linode VPC and Cloud Firewall to Quake AI
Network
Migrate from Vultr VPC 2.0 and Firewall Groups to Quake AI
Network
Migrating from AWS to Quake AI
Platform
Migrating from Azure to Quake AI
Platform
Migrating from DigitalOcean to Quake AI
Platform
Migrating from GCP to Quake AI
Platform
Migrating from Hetzner Cloud to Quake AI
Platform
Migrating from Linode (Akamai Cloud Computing) to Quake AI
Platform
Migrating from Vultr to Quake AI
Platform
Network Migration Guides
Network
deployment
Build a private network with two virtual machines
Network
Deploy a bursty-GPU control plane with a queue and workers
Compute
Deploy a private container registry with OpenTofu
Automation
Deploy a Redis or Valkey cache with the redis-cache template
Automation
Deploy a regional edge cache with the edge-cache template
Automation
Deploy a self-hosted CI runner
Compute
Deploy a self-hosted git forge and CI with OpenTofu
Automation
Deploy an API gateway with the api-gateway template
Automation
Deploy an edge reverse proxy with the edge-reverse-proxy template
Automation
Deploy an edge tunnel gateway with the edge-tunnel-gateway template
Automation
Deploy an edge WAF with the edge-waf template
Automation
Deploy an inference gateway with OpenTofu
Automation
Deploy edge functions with the edge-functions template
Automation
Deploy the development environment template with OpenTofu
Automation
Deploy the full-stack application template with OpenTofu
Automation
Deploy the Kubernetes cluster bootstrap template with OpenTofu
Automation
Deploy the monitoring stack template with OpenTofu
Automation
Deploy the MySQL/MariaDB database template with OpenTofu
Automation
Deploy the private network + VPN template with OpenTofu
Automation
Deploy the self-managed PostgreSQL template with OpenTofu
Automation
Deploy the three-tier application template with OpenTofu
Automation
Deploy the WordPress + MySQL template with OpenTofu
Automation
Templates
Airbyte ingestion (ELT)
→Apache Airflow orchestration
→Apache Superset BI
→API gateway
→Appsmith internal tools
→Cal.com scheduling
→ClickHouse analytical column store
→Coolify host
→Development Environment
→Edge cache
→Edge functions
→Edge reverse proxy
→Edge tunnel gateway
→Edge web application firewall appliance
→Excalidraw whiteboard
→Feast feature store
→Forgejo Git and CI
→Full-Stack Application
→Harbor registry
→Heat Simple Stack
→Inference gateway
→Infisical secrets management
→JupyterHub notebook server
→Kubernetes Cluster Bootstrap
→Mattermost team chat
→Metabase BI dashboards
→MinIO + Apache Iceberg lakehouse
→MLflow experiment tracking
→Monitoring Stack (Prometheus + Grafana)
→MySQL/MariaDB Database
→n8n workflow automation
→Nextcloud files and collaboration
→Outline team knowledge base
→Plane project management
→Private Network + VPN
→Qdrant vector database
→Redis / Valkey cache
→Redpanda Kafka-API streaming
→Selenium Grid testing
→Self-hosted error telemetry (GlitchTip)
→Self-hosted OIDC identity provider (Keycloak)
→Self-Managed PostgreSQL
→Streamlit data-app host
→Supabase self-host stack
→Three-Tier Application
→Trino federated query engine
→Umami self-hosted analytics
→Unleash feature flags
→Uptime Kuma status and monitoring
→WordPress + MySQL on Compute
→