Skip to content

Network

Overview · Updated May 2026

Coming from another cloud?

▸AWS·Amazon Virtual Private Cloud

Amazon Virtual Private Cloudhigh

  • AWS VPC is regional with CIDR /16-/28.
  • OpenStack Networks project-scoped L2 with flexible CIDR.
  • AWS requires IGW for public.
  • OpenStack provider nets or floating IPs.
AWS docs ↗
▸Azure·Virtual Network (VNet)

Virtual Network (VNet)high

  • Azure VNets are strictly regional Layer 3 overlays scoped to one subscription with no L2 VLAN support ().
  • VNets and subnets creation free, but subnets min /29 with Azure reserving 5 IPs per subnet ().
  • Managed via ARM REST APIs/PowerShell/CLI vs Neutron REST API.
  • Isolated per subscription; peering for cross-VNet connectivity vs OpenStack project networks connected via routers.
Azure docs ↗
▸DigitalOcean·VPC (VPC Network)

VPC (VPC Network)high

  • Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
  • Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
  • NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
  • Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
DigitalOcean docs ↗
▸Google Cloud·VPC

This Quake AI feature maps to Google Cloud’s VPC.

▸Hetzner·Networks

Networkshigh

  • Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs.
  • CCM supports route controller for pod networking when enabled; no native provider networks like OpenStack.
  • Limited to Hetzner regions, IPv4 only for private (IPv6 public).
  • Networks are free with no usage charges, unlike potential metering in OpenStack clouds ().
Hetzner docs ↗

Network

Every workload on Quake AI needs a network path to other instances, to the internet, or both. The Network service gives you the building blocks: isolated project networks with subnets and DHCP, routers for inter-network traffic, floating IPs for public access, and security groups for per-port firewall rules.

OpenStack Neutron backs Network. For details on how Quake AI implements OpenStack, see How Quake AI uses OpenStack.

What you can do#

How it works#

InternetQuick TestingProductionPublicEphemeralInstanceRouterFloating IPSecurity GroupsPrivate NetworkWeb ServerApp ServerDatabase direct attachpublic IP
Click to zoom
Network topology: PublicEphemeral for quick testing vs. production path with private networks, routers, and floating IPs.

A Quake AI project starts with two pre-built networks. PublicEphemeral lets you attach an instance directly for quick testing; the instance gets a public IP but is fully exposed. PublicStatic is the production path: your instances live on private networks you create, and you route external traffic through routers and floating IPs with security groups filtering every connection.

The typical pattern is: create a network and one or more subnets that define IP ranges and DHCP settings. Attach a router to connect your network to the external gateway. Allocate floating IPs and associate them with public instances. Apply security groups to control inbound and outbound traffic at the port level.

For applications that need traffic distribution or TLS termination, run a reverse proxy such as Caddy, Nginx, HAProxy, or Traefik on a Compute instance. A CDN or WAF can provide an external edge in front of that origin. For site-to-site connectivity, deploy a self-managed VPN gateway (WireGuard or IPsec) on a Compute instance; see the Private Network + VPN template for an OpenTofu configuration.

Get started#

To set up networking for a new project, start with Create a network. If you already have instances running and need to expose them, see Allocate floating IP addresses.

Key concepts#

Concepts

  • Floating IPs: The Network service (OpenStack Neutron) implements floating IPs as public addresses you attach to an instance on a private network when you need reachability from the internet or another external...
  • IP Address Management: Instances on Quake AI receive at least one private IP address from the subnet they connect to. How that address is allocated, how it reaches the guest OS, and what happens when you need multiple...
  • Networks: Networks are isolated Layer 2 segments that give your instances connectivity. Instances attach to at least one network; most production deployments use private networks with routers and floating IPs...
  • Ports: The Network service (OpenStack Neutron) implements ports as the logical attachment between a network and a device, most often a VM’s virtual NIC, but also router interfaces and other integrations...
  • Routers: The Network service (OpenStack Neutron) implements routers as virtual layer-3 gateways inside your project. They connect private subnets to each other and, when you set an external gateway, to...
  • Security Groups: The Network service (OpenStack Neutron) implements security groups as stateful packet filters attached to instance ports. Each rule describes allowed traffic by direction (ingress or egress), IP...

Security considerations#

The platform provides network isolation between projects at the infrastructure level. You configure security groups to control traffic to and from your instances, TLS on application servers or reverse proxies, and private networks to keep internal traffic off the public internet. For a cross-service view of security topics, see Security.

Guides and reference#

Console guides#

How-to guides#

  • How to Allocate Floating IP Addresses: Floating IPs are public IP addresses that you can assign to instances on private networks. Allocate a floating IP from the public pool, then associate it with an instance to make it reachable from the...
  • How to Create a Network: Create a private network with a subnet to connect your instances. Each network requires at least one subnet that defines the IP address range, DNS servers, and gateway settings.
  • How to Create a Router: Create a router to connect a private network to an external network. Routers enable instances on private subnets to reach the internet and allow floating IP addresses to route traffic to your...
  • How to Create a Security Group: Security groups act as virtual firewalls that control inbound and outbound traffic to your instances. Create a security group to define a set of rules that specify which traffic is allowed.
  • How to Create Security Group Rules: Add rules to an existing security group to control which traffic can reach your instances. Rules define the protocol, port range, direction, and source for allowed traffic.
  • How to Front a Quake AI Workload with a Web Application Firewall: Put a web application firewall (WAF) in front of an HTTP workload so attack traffic (SQL injection, cross-site scripting, and other OWASP Top 10 patterns) is filtered before it reaches your instances...
  • How to Issue and Auto-renew a TLS Certificate with Let's Encrypt: Use Certbot on a Quake AI instance to obtain and renew a TLS certificate from Let's Encrypt. Terminate TLS on the application instance or on a self-managed reverse proxy.
  • How to Point a Domain at a Quake AI Resource: Publish a hostname that resolves to a workload on Quake AI. Allocate a public address on the platform, then create an A or CNAME record at your domain registrar or DNS host. Quake AI does not host...
  • How to Put a CDN in Front of a Quake AI Workload: Place a third-party content delivery network (CDN) in front of a Quake AI origin to cache static assets and absorb edge traffic. This guide covers the Quake AI origin configuration and the values your...
  • How to Run Blue/green or Canary Deployments on Quake AI: Cut over to a new application version by routing traffic through a reverse proxy that you operate. This guide uses HAProxy because its runtime API can change backend weights without restarting the...
  • How to Self-host Authoritative DNS on Quake AI: Run an authoritative DNS server you operate on a Quake AI instance. Quake AI does not host managed DNS for your domains. You launch a VM, install PowerDNS, publish zones, and delegate the domain from...
  • How to Set Up a Site-to-site or Remote-access VPN to Quake AI: Connect an on-premises network or remote clients to a private Quake AI network by running a VPN gateway on a Compute instance.
  • How to Set Up SSH Bastion Access into a Private Subnet: Reach instances on a private subnet through a single hardened jump host, so the private instances never need a public address.

CLI reference#

API reference#

Compute instances are the primary consumers of network resources; every instance attaches to at least one network, and security groups can guard each one. See Compute. For encrypted object storage access over the network, see Storage.

Was this page helpful?