How to Create a Network
Coming from another cloud?
▸AWS·Amazon Virtual Private Cloud
Amazon Virtual Private Cloud
- AWS VPC is regional with CIDR /16-/28.
- OpenStack Networks project-scoped L2 with flexible CIDR.
- AWS requires IGW for public.
- OpenStack provider nets or floating IPs.
▸Azure·Virtual Network (VNet)
Virtual Network (VNet)
- Azure VNets are strictly regional Layer 3 overlays scoped to one subscription with no L2 VLAN support ().
- VNets and subnets creation free, but subnets min /29 with Azure reserving 5 IPs per subnet ().
- Managed via ARM REST APIs/PowerShell/CLI vs Neutron REST API.
- Isolated per subscription; peering for cross-VNet connectivity vs OpenStack project networks connected via routers.
▸DigitalOcean·VPC (VPC Network)
VPC (VPC Network)
- Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
- Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
- NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
- Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
▸Google Cloud·VPC Network
VPC Network
- GCP VPC is global (spans all regions) whereas OpenStack Neutron networks are project-scoped and region-local.
- GCP uses shared VPC for cross-project networking (requires org-level config); OpenStack uses shared networks via admin.
- Subnets in GCP are regional, auto-mode creates one per region automatically; OpenStack requires explicit subnet creation.
- GCP VPC Flow Logs per-subnet; OpenStack has no native equivalent without external tools.
▸Hetzner·Networks
Networks
- Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs.
- CCM supports route controller for pod networking when enabled; no native provider networks like OpenStack.
- Limited to Hetzner regions, IPv4 only for private (IPv6 public).
- Networks are free with no usage charges, unlike potential metering in OpenStack clouds ().
How to create a network
Create a private network with a subnet to connect your instances. Each network requires at least one subnet that defines the IP address range, DNS servers, and gateway settings.
Prerequisites
- ConsoleLogged in to the Quake AI console
- CLIOpenStack CLI installed and authenticated (
clouds.yamloropenrcsourced) - APIAPI token generated with
$OS_TOKENand service endpoint variables set - TerraformOpenTofu installed with Quake AI provider configured
Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.
Create the network and subnet#
Verify the result#
See also#
- Network API Reference: full parameter documentation for the Network API
- Network CLI reference
- Network API reference
- How to create a router
- How to create a security group
- Network console
- Network service
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 03.06.2026