How to Create Security Group Rules
How to create security group rules
Add rules to an existing security group to control which traffic can reach your instances. Rules define the protocol, port range, direction, and source for allowed traffic.
Prerequisites
- ConsoleLogged in to the Quake AI console
- CLIOpenStack CLI installed and authenticated (
clouds.yamloropenrcsourced) - APIAPI token generated with
$OS_TOKENand service endpoint variables set
Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.
You need an existing security group to add rules to.
Understanding rules#
Security group rules control traffic using these properties:
- Protocol: TCP, UDP, or ICMP (selected via the Protocol dropdown, which also offers presets and wildcards described below)
- Port: single port (for example,
22) or range (for example,80:160; note the colon separator the live UI accepts, not a dash) - Direction: Ingress (inbound) or Egress (outbound)
- Source: All traffic (
0.0.0.0/0), a CIDR range, or another security group - Ether Type: IPv4 or IPv6
The default security group allows all outbound traffic and all inbound traffic from other members of the same group. Custom groups start with only egress rules.
Protocol dropdown contents#
The Create Rule dialog's Protocol dropdown exposes ten options in the following order on the live the Console:
| Order | Option | Behavior |
|---|---|---|
| 1 | Custom TCP Rule | Free-form TCP rule; you set Port, Direction, Source. |
| 2 | Custom UDP Rule | Free-form UDP rule; same fields as above. |
| 3 | Custom ICMP Rule | Free-form ICMP rule (no port input). |
| 4 | All Proto | Wildcard: allow every protocol (TCP, UDP, ICMP, etc.) on the matched flow. |
| 5 | All TCP | Wildcard: allow every TCP port. |
| 6 | All UDP | Wildcard: allow every UDP port. |
| 7 | All ICMP | Wildcard: allow every ICMP type. |
| 8 | SSH | TCP/22 preset. Sets the protocol and hides the Port and Port Type fields. |
| 9 | SMTP | TCP/25 preset. Same hide-fields behavior. |
| 10 | DNS | TCP and UDP/53 preset. Same hide-fields behavior. |
The quickstart's Create a security group section walks the SSH preset end-to-end against a live security group.
Add rules to a security group#
Verify the result#
See also#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 04.06.2026