Skip to content

VPC on Quake AI

Explanation · Updated Jun 2026

Coming from another cloud?

▸AWS·Amazon Virtual Private Cloud

Amazon Virtual Private Cloudhigh

  • AWS VPC is regional with CIDR /16-/28.
  • OpenStack Networks project-scoped L2 with flexible CIDR.
  • AWS requires IGW for public.
  • OpenStack provider nets or floating IPs.
AWS docs ↗
▸Azure·Virtual Network (VNet)

Virtual Network (VNet)high

  • Azure VNets are strictly regional Layer 3 overlays scoped to one subscription with no L2 VLAN support ().
  • VNets and subnets creation free, but subnets min /29 with Azure reserving 5 IPs per subnet ().
  • Managed via ARM REST APIs/PowerShell/CLI vs Neutron REST API.
  • Isolated per subscription; peering for cross-VNet connectivity vs OpenStack project networks connected via routers.
Azure docs ↗
▸DigitalOcean·VPC (VPC Network)

VPC (VPC Network)high

  • Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
  • Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
  • NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
  • Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
DigitalOcean docs ↗
▸Google Cloud·VPC Network

VPC Networkhigh

  • GCP VPC is global (spans all regions) whereas OpenStack Neutron networks are project-scoped and region-local.
  • GCP uses shared VPC for cross-project networking (requires org-level config); OpenStack uses shared networks via admin.
  • Subnets in GCP are regional, auto-mode creates one per region automatically; OpenStack requires explicit subnet creation.
  • GCP VPC Flow Logs per-subnet; OpenStack has no native equivalent without external tools.
Google Cloud docs ↗
▸Hetzner·Networks

Networkshigh

  • Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs.
  • CCM supports route controller for pod networking when enabled; no native provider networks like OpenStack.
  • Limited to Hetzner regions, IPv4 only for private (IPv6 public).
  • Networks are free with no usage charges, unlike potential metering in OpenStack clouds ().
Hetzner docs ↗

VPC on Quake AI

Quake AI does not expose a single object named VPC or virtual private cloud. The same job is done with networks (including subnets as IP ranges inside a network), routers (routing and NAT between segments), and floating IPs (stable public addresses on private instances).

If you are used to AWS VPC, Azure VNet, or GCP VPC networks, map that mental model to these Neutron primitives inside a project.

How the pieces map#

VPC habitOn Quake AI
One isolated network per environmentCreate a private network per tier or environment
Subnets in availability zonesSubnets with CIDR blocks on that network
Internet gateway + route tablesRouter attached to PublicStatic plus static routes
Elastic IP on a private instanceFloating IP associated to the instance port
Security group / NACLSecurity groups on ports (stateful rules)

Each project scopes networks by default. Instances on the same private network reach each other at Layer 2; routers provide north-south paths and NAT.

On Quake AI#

Built-in external networks include PublicEphemeral (direct provider attachment for quick tests) and PublicStatic (routed access through a router). Production layouts typically use a private network, a router, and floating IPs rather than attaching workloads directly to a public provider network.

What other providers call this#

ProviderTheir termQuake AI mapping
AWSVPCNetworks + subnets + routers
AzureVirtual network (VNet)Networks + subnets + routers
Google CloudVPC networkNetworks + subnets + routers
DigitalOceanVPCNetworks + subnets (region-scoped attachment rules differ)
HetznerNetworkPrivate networks attached to servers

Related content

Pages

How-tos

migration

deployment

Templates

Was this page helpful?