Skip to content

Network how-to guides

Overview

Network how-to guides

Procedural guides for the Network service: provisioning networks and subnets, attaching routers, allocating floating IPs, defining security groups, configuring DNS, and protecting public endpoints with TLS, a CDN, or a WAF. Use these when you have a specific outcome in mind. For background on the underlying primitives, read the concept pages.

  • How to Allocate Floating IP Addresses: Floating IPs are public IP addresses that you can assign to instances on private networks. Allocate a floating IP from the public pool, then associate it with an instance to make it reachable from the...
  • How to Create a Network: Create a private network with a subnet to connect your instances. Each network requires at least one subnet that defines the IP address range, DNS servers, and gateway settings.
  • How to Create a Router: Create a router to connect a private network to an external network. Routers enable instances on private subnets to reach the internet and allow floating IP addresses to route traffic to your...
  • How to Create a Security Group: Security groups act as virtual firewalls that control inbound and outbound traffic to your instances. Create a security group to define a set of rules that specify which traffic is allowed.
  • How to Create Security Group Rules: Add rules to an existing security group to control which traffic can reach your instances. Rules define the protocol, port range, direction, and source for allowed traffic.
  • How to Front a Quake AI Workload with a Web Application Firewall: Put a web application firewall (WAF) in front of an HTTP workload so attack traffic (SQL injection, cross-site scripting, and other OWASP Top 10 patterns) is filtered before it reaches your instances...
  • How to Issue and Auto-renew a TLS Certificate with Let's Encrypt: Use Certbot on a Quake AI instance to obtain and renew a TLS certificate from Let's Encrypt. Terminate TLS on the application instance or on a self-managed reverse proxy.
  • How to Point a Domain at a Quake AI Resource: Publish a hostname that resolves to a workload on Quake AI. Allocate a public address on the platform, then create an A or CNAME record at your domain registrar or DNS host. Quake AI does not host...
  • How to Put a CDN in Front of a Quake AI Workload: Place a third-party content delivery network (CDN) in front of a Quake AI origin to cache static assets and absorb edge traffic. This guide covers the Quake AI origin configuration and the values your...
  • How to Run Blue/green or Canary Deployments on Quake AI: Cut over to a new application version by routing traffic through a reverse proxy that you operate. This guide uses HAProxy because its runtime API can change backend weights without restarting the...
  • How to Self-host Authoritative DNS on Quake AI: Run an authoritative DNS server you operate on a Quake AI instance. Quake AI does not host managed DNS for your domains. You launch a VM, install PowerDNS, publish zones, and delegate the domain from...
  • How to Set Up a Site-to-site or Remote-access VPN to Quake AI: Connect an on-premises network or remote clients to a private Quake AI network by running a VPN gateway on a Compute instance.
  • How to Set Up SSH Bastion Access into a Private Subnet: Reach instances on a private subnet through a single hardened jump host, so the private instances never need a public address.
Was this page helpful?