# Network Migration Guides

Source: https://docs.quake.ai/docs/network/migration
Markdown: https://docs.quake.ai/docs/network/migration.md

---

# Network migration guides

Move your networking configuration to Quake AI from another provider. Quake AI's network layer runs [OpenStack Neutron](/resources/migration/openstack) with OVN as the SDN backend, providing software-defined networking with five core objects: **networks**, **subnets**, **routers**, **floating IPs**, and **security groups**.

Every provider's networking model maps to this same set of Neutron primitives, but the translation complexity varies. DigitalOcean and Hetzner map almost directly. AWS, GCP, and Azure introduce constructs (NACLs, global VPCs, dual NSG layers) that require rethinking instead of one-to-one porting.

## Choose your source provider

<UseCaseGrid>
<UseCaseCard
  title="Migrate from AWS VPC"
  description="VPC subnets, NACLs, IGW, and NAT Gateway collapse into Neutron's router model. Includes security group translation, ALB replacement, and Route 53 cutover."
  href="/docs/network/migration/migrate-from-aws-vpc"
  difficulty="intermediate"
  services={["Network"]}
/>
<UseCaseCard
  title="Migrate from DigitalOcean VPC"
  description="Cloud Firewalls map cleanly to security groups. Reserved IPs to floating IPs. The closest conceptual match after Hetzner."
  href="/docs/network/migration/migrate-from-do-vpc"
  difficulty="intermediate"
  services={["Network"]}
/>
<UseCaseCard
  title="Migrate from Hetzner Cloud Networks"
  description="Closest operational model to Neutron. Cloud Firewalls, Floating IPs, and private Networks all have near-identical equivalents."
  href="/docs/network/migration/migrate-from-hetzner-networks"
  difficulty="intermediate"
  services={["Network"]}
/>
<UseCaseCard
  title="Migrate from GCP VPC"
  description="Global VPC must become per-region Neutron deployments. Firewall deny rules and hierarchical policies collapse into flat, allow-only security groups."
  href="/docs/network/migration/migrate-from-gcp-vpc"
  difficulty="intermediate"
  services={["Network"]}
/>
<UseCaseCard
  title="Migrate from Azure VNet"
  description="Dual NSG layers (subnet + NIC) merge into single port-level security groups. Application Gateway WAF has no equivalent."
  href="/docs/network/migration/migrate-from-azure-vnet"
  difficulty="intermediate"
  services={["Network"]}
/>
<UseCaseCard
  title="Migrate from Linode VPC"
  description="Linode VPC collapses network and subnet into one object; Neutron exposes them separately. Cloud Firewalls map to per-port security groups. Replace NodeBalancers with a reverse proxy or external edge."
  href="/docs/network/migration/migrate-from-linode-vpc"
  difficulty="intermediate"
  services={["Network"]}
/>
<UseCaseCard
  title="Migrate from Vultr VPC 2.0"
  description="Vultr VPC 2.0 keeps network and subnet as one object; Neutron exposes them separately. Firewall Groups map to per-port security groups. Replace Vultr Load Balancers with a reverse proxy or external edge."
  href="/docs/network/migration/migrate-from-vultr-vpc"
  difficulty="intermediate"
  services={["Network"]}
/>
</UseCaseGrid>

## Quake AI networking model

Quake AI offers two network models depending on your use case.

### PublicEphemeral (dev/testing)

Your instance receives a DHCP-assigned public IP directly on a provider network. This model uses no router or NAT. The address changes when the instance restarts, not only on rebuild. Use this model for throwaway dev environments; for any workload that needs a stable public address, use PublicStatic with floating IPs.

### PublicStatic (production)

A private network (RFC 1918 CIDR) with a Neutron router connected to the external network. The router provides SNAT for outbound traffic. Floating IPs provide stable inbound access via DNAT. This is the model you use in production and the target for all migration guides.

| Neutron object | Role | Equivalent across providers |
|---|---|---|
| Network | L2 broadcast domain (VXLAN overlay via OVN) | VPC, VNet, hcloud Network |
| Subnet | IP range with DHCP and gateway | Subnet (all providers) |
| Router | L3 gateway, SNAT outbound, floating IP DNAT inbound | IGW + NAT GW (AWS), Cloud NAT (GCP), NAT Gateway (Azure), implicit public NIC or NAT Gateway (DO), implicit (Hetzner) |
| Floating IP | Static public IPv4, maps 1:1 to a port | Elastic IP (AWS), Reserved IP (DO), Floating IP (Hetzner), Static External IP (GCP), Public IP (Azure) |
| Security Group | Stateful, allow-only, per-port ACL (OVN ACLs) | Security Group (AWS), Cloud Firewall (DO/Hetzner), Firewall Rule (GCP), NSG (Azure) |
| Reverse proxy instance | HAProxy, Nginx, Caddy, Traefik, or Envoy | ALB/NLB (AWS), LB (DO/Hetzner), Cloud LB (GCP), Azure LB/App Gateway |

## What maps cleanly across all providers

These networking primitives have direct, configuration-only equivalents on Quake AI:

- Static/reserved public IPs → Neutron floating IPs
- Stateful, allow-only instance firewall rules → Neutron security groups
- Private network segmentation → Neutron networks and subnets

## What requires rethinking

- **Managed DNS**: Quake AI has no managed DNS service. Route 53, Cloud DNS, Azure DNS, Hetzner DNS, and DigitalOcean DNS must be migrated to an external provider (Cloudflare, NS1, self-hosted BIND)
- **Managed load balancing**: Deploy a reverse proxy such as HAProxy, Nginx, Caddy, Traefik, or Envoy on a Compute instance. Assign it a floating IP and route to private application instances
- **WAF / web application firewall**: Use an application-layer proxy with a WAF module or a CDN/WAF edge service
- **VPN-as-a-Service**: Not available. Site-to-site VPN must be implemented with WireGuard or OpenVPN on a dedicated instance
- **IPv6**: Not documented on Quake AI. Providers with native IPv6 require a transition plan
- **Network peering**: No VPC/VNet peering equivalent. DigitalOcean VPC peering is now generally available, and Hetzner does not offer peering. Cross-project communication on Quake AI must traverse the external network or use a VPN overlay

## Egress pricing model comparison

Quake AI includes bandwidth in the instance flavor pricing with no per-GB egress charge. The five providers below differ in how they model outbound transfer; current rates live on each provider's pricing page.

| Provider | Egress model | Notes |
|---|---|---|
| AWS | Per-GB metered after small allowance | NAT Gateway processing also metered per-GB. See [AWS pricing](https://aws.amazon.com/pricing/) |
| GCP | Per-GiB metered, destination-dependent | Premium and Standard network tiers differ. See [GCP network pricing](https://cloud.google.com/vpc/network-pricing) |
| Azure | Per-GB metered after small allowance | Rates vary by region. See [Azure bandwidth pricing](https://azure.microsoft.com/en-us/pricing/details/bandwidth/) |
| DigitalOcean | Included allowance per Droplet, per-GiB overage | Pooled across team. See [DigitalOcean pricing](https://www.digitalocean.com/pricing) |
| Hetzner | Included monthly allowance differs EU vs US | Per-GB overage where applicable. See [Hetzner pricing](https://www.hetzner.com/cloud) |
| Quake AI | Included in flavor pricing | Bandwidth scales with vCPUs |

## See also

- [Migrate to Quake AI](/resources/migration): cross-service migration hub
- [Create a network](/docs/network/how-to/create-network): provision your first Neutron network
- [Create a security group](/docs/network/how-to/create-security-group): configure firewall rules
- [Allocate floating IPs](/docs/network/how-to/allocate-floating-ips): assign static public addresses
- [Edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy): deploy a self-managed traffic entry point
- [Compute migration guides](/docs/compute/migration): if you also need to move VMs
- [Object storage migration](/docs/object/migration): if you also need to move storage
