Skip to content

Migrate from AWS VPC to Quake AI

Migration · Updated Jun 2026

Coming from another cloud?

▸AWS·Amazon Virtual Private Cloud, Security Groups, ELB, Route53

Amazon Virtual Private Cloudhigh

  • AWS VPC is regional with CIDR /16-/28.
  • OpenStack Networks project-scoped L2 with flexible CIDR.
  • AWS requires IGW for public.
  • OpenStack provider nets or floating IPs.
AWS docs ↗

Security Groupshigh

  • AWS stateful auto-response.
  • OpenStack stateless explicit.
  • OpenStack port/project.
  • AWS default inbound deny/outbound all.
AWS docs ↗

Migrate from AWS VPC to Quake AI

AWS VPC exposes more networking primitives than the other major cloud providers, so it has the largest gap to bridge when migrating to Quake AI. The core shift: AWS layers subnets, an Internet Gateway, NAT Gateways, route tables, and NACLs into a multi-component stack. On Quake AI, the Network service (OpenStack Neutron) composes three objects: a network, a subnet, and a router. The router replaces both the Internet Gateway and NAT Gateway in a single resource.

Service mapping#

AWS to Quake AI

AWS serviceQuake AI equivalentKey difference
Elastic IP addressesFloating IPsAWS charges idle EIPs. OpenStack floating IPs free/pool-limited. AWS regional instance/ENI. OpenStack project port.
NAT GatewayNATAWS managed HA per AZ hourly/GB. OpenStack router SNAT L3 agent/OVN. OpenStack basic SNAT. OpenStack router-limited.
Elastic Load BalancingNetworkQuake AI workloads use a self-managed reverse proxy or Kubernetes LoadBalancer Service. AWS hourly/LCU billing. OpenStack VM billing. AWS... see details
Amazon VPC + VPC CNINetworkingQuake AI uses per-cluster private networks and routers for Kubernetes; EKS uses a customer VPC with ENI pod networking. Quake AI K8s uses... see details
Amazon Virtual Private CloudNetworksAWS VPC is regional with CIDR /16-/28. OpenStack Networks project-scoped L2 with flexible CIDR. AWS requires IGW for public. OpenStack... see details
Elastic Network InterfacesPortsNo notable divergence
Route TablesRoutersAWS per subnet/VPC main. OpenStack L3 routers distributed/central. AWS local intra-VPC implicit. OpenStack BGP-LS opt.
Security PillarSecurityNo notable divergence
Security GroupsSecurity GroupsAWS stateful auto-response. OpenStack stateless explicit. OpenStack port/project. AWS default inbound deny/outbound all.
SubnetsSubnetsAWS subnets single AZ. AWS public/private by routes. OpenStack by network type. AWS IPv6-only; OpenStack dual-stack.

Prerequisites#

  • A Quake AI account with application credentials
  • The OpenStack CLI installed and configured
  • An inventory of your AWS VPC resources: subnets, security groups, NACLs, Elastic IPs, load balancers, and Route 53 zones
  • An SSH key pair imported to Quake AI (run openstack keypair create with --public-key)

Topology mapping#

The AWS public-subnet/IGW/NACL stack collapses into a single Neutron router with an external gateway. NACLs are dropped entirely. Security groups map closely.

AWS VPCQuake AI NeutronInternet GatewayPublic SubnetPrivate SubnetNAT GatewayNACLElastic IPSecurity GroupRouter (gateway + SNAT)Tenant NetworkSubnetFloating IPSecurity Group subnet-levelinstance-levelport-levelmaps to
Click to zoom
AWS VPC components map to a single Neutron router plus tenant network with security groups and floating IPs
AWS conceptNeutron equivalentNotes
VPCNetwork (project scope)No strict regional boundary in Neutron; region is a deployment choice
Subnet (public)Subnet on tenant network + floating IPFloating IP provides public access
Subnet (private)Subnet on tenant networkStandard model
Internet GatewayRouter external gatewayImplicit when you create a router with an external network
NAT GatewayRouter (SNAT)Router provides outbound SNAT automatically; no separate object or charge
Route TableRouter static routesopenstack router add route for custom entries
NACLNo equivalentAbsorb allow rules into security groups; see below
Security GroupSecurity GroupSame operating model: both stateful, allow-only, per-instance
Elastic IPFloating IPRegion-scoped, re-assignable; one per port
ENIPortVirtual NIC; security groups bind to ports
VPC PeeringNo equivalentNo network peering on Quake AI
Transit GatewayNo equivalentNo multi-VPC routing hub
VPC EndpointNo equivalentNo PrivateLink-style internal service access

Set up the Neutron equivalent#

Create the network, subnet, and router that replace your VPC stack:

bash
openstack network create MY_NETWORK

openstack subnet create MY_SUBNET \
  --network MY_NETWORK \
  --subnet-range 10.0.0.0/24 \
  --gateway 10.0.0.1 \
  --dns-nameserver 8.8.8.8

openstack router create MY_ROUTER
openstack router set MY_ROUTER --external-gateway PublicStatic
openstack router add subnet MY_ROUTER MY_SUBNET

This single router replaces your Internet Gateway (inbound through floating IPs), NAT Gateway (outbound through SNAT), and route tables (default route through the router).

Security rule translation#

AWS has two firewall layers: Security Groups (stateful, allow-only, per-ENI) and NACLs (stateless, allow+deny, per-subnet). Neutron has one layer: Security Groups (stateful, allow-only, per-port).

DimensionAWS Security GroupsAWS NACLsNeutron Security Groups
Enforcement levelInstance (ENI)SubnetPort
StatefulnessStatefulStatelessStateful
Rule modelAllow-onlyAllow and denyAllow-only
EvaluationAll rules additiveOrdered by rule numberAll rules additive
Source typesCIDR, Security Group IDCIDR onlyCIDR, Security Group ID
Default inboundDeny-allAllow-all (default NACL only; custom NACLs start with no rules, effectively deny-all)Deny-all

Translating NACLs#

NACLs have no Neutron equivalent. For most deployments, the migration approach is:

  1. Convert NACL allow rules to security group rules. Any traffic your NACLs explicitly allowed that your security groups do not already cover needs a new SG rule.
  2. Drop NACL deny rules. Neutron's default deny-all ingress achieves the same effect. If a NACL denied traffic that a broad SG allow rule would permit (e.g., deny 10.0.0.0/8 within a 0.0.0.0/0 allow), split the SG allow into specific non-overlapping CIDRs.
  3. Accept single-layer security. Neutron security groups are functionally comparable to AWS SGs. The NACL layer is an AWS-specific defense-in-depth measure that many deployments do not rely on.

3-tier app example#

AWS source:

  • NACL on public subnet: allow HTTP/HTTPS from internet, deny RFC 1918
  • web-sg: inbound TCP 80, 443 from 0.0.0.0/0
  • app-sg: inbound TCP 8080 from web-sg
  • db-sg: inbound TCP 5432 from app-sg

Neutron target:

bash
openstack security group create MY_SG_WEB
openstack security group rule create MY_SG_WEB \
  --protocol tcp --dst-port 80 --remote-ip 0.0.0.0/0 --ingress
openstack security group rule create MY_SG_WEB \
  --protocol tcp --dst-port 443 --remote-ip 0.0.0.0/0 --ingress

openstack security group create MY_SG_APP
openstack security group rule create MY_SG_APP \
  --protocol tcp --dst-port 8080 --remote-group MY_SG_WEB --ingress

openstack security group create MY_SG_DB
openstack security group rule create MY_SG_DB \
  --protocol tcp --dst-port 5432 --remote-group MY_SG_APP --ingress

You drop the NACLs. The NACL that denied RFC 1918 to the public subnet is unnecessary because Neutron does not route non-addressed traffic to your instances. You replace the NACL that denied port 3389/RDP from the internet by omitting an allow rule for port 3389 on MY_SG_WEB.

Load balancer migration#

Replace an AWS load balancer with a reverse proxy that you operate, or with an external edge service.

AWS sourceQuake AI migration pattern
Application Load BalancerHAProxy, Nginx, Caddy, Traefik, or Envoy on a Compute instance
Network Load BalancerHAProxy or Nginx stream proxy on a Compute instance
AWS WAF on ALBExternal CDN/WAF in front of the Quake AI origin
Global Accelerator or cross-region routingExternal DNS traffic manager or CDN

Assign a floating IP to the proxy instance and keep application instances on a private network. Configure health checks and backend pools in the proxy. Install certificates on the proxy with Certbot or let Caddy manage ACME issuance and renewal.

Floating IP setup#

AWS Elastic IPNeutron Floating IP
Allocated to account, assigned to ENIAllocated to project, assigned to port
Public IPv4 addresses are billed hourly since Feb 2024, whether attached, idle, or ephemeral; the first attached EIP was free before that change. See AWS IPv4 pricing.Included in Quake AI instance pricing
Can attach to secondary ENI IPsOne floating IP per port
IPv6 supportedIPv6 not documented on Quake AI

Allocate and associate a floating IP:

bash
openstack floating ip create PublicStatic
openstack server add floating ip MY_INSTANCE FLOATING_IP_ADDRESS

DNS cutover#

Quake AI has no managed DNS service. Route 53 must be replaced by an external provider (Cloudflare, NS1, self-hosted BIND).

  1. Lower TTLs: 24-48 hours before cutover, reduce all record TTLs to 60-300 seconds. The NS record TTL (typically 172,800 seconds) must be reduced first; wait the full TTL period before continuing.
  2. Export records: Use the AWS Console or CLI to export the hosted zone.
  3. Translate alias records: Route 53 alias records (A records pointing to ELB, CloudFront) have no standard DNS equivalent. Create standard A or CNAME records that point to the reverse proxy floating IP or external edge hostname.
  4. Import at new provider: Most DNS providers accept BIND zone file imports or Terraform configuration.
  5. Validate: dig @NEW_NAMESERVER example.com A
  6. Update registrar NS records: This step completes the cutover. DNS propagation takes up to 48 hours globally.
  7. Monitor for 48 hours: Keep the Route 53 zone active during monitoring; rollback by reverting registrar NS records.
  8. Restore TTLs: Raise TTLs to 3600-86400 after successful cutover.

Validation checklist#

After completing the migration, verify:

  • Neutron network, subnet, and router are operational (openstack router show MY_ROUTER)
  • Security group rules match your AWS SG rules (compare rule counts and port/CIDR combinations)
  • NACL intent is covered by security group rules (no implicit allow gaps)
  • Floating IPs are associated with the correct instance ports
  • Reverse proxy health checks pass for application backends
  • TLS termination works on the reverse proxy or external edge
  • DNS records resolve to the correct Quake AI floating IP or external edge hostname
  • Applications respond correctly through the full network path
  • Egress traffic routes through the router (test outbound connectivity from instances)

Provider-specific gotchas#

TopicDetail
Egress pricing cliffAWS bills egress per-GB after a small free allowance, and NAT Gateway adds both an hourly and a per-GB charge. Quake AI includes bandwidth in flavor pricing. See AWS pricing.
No Availability ZonesAWS multi-AZ subnet strategies do not apply. Quake AI uses regions, not AZs. HA requires multi-region deployment with application-layer or DNS-level failover.
VPC Endpoints / PrivateLinkNo equivalent. Workloads that used VPC Endpoints for S3 or other AWS services will use direct internet egress after migration.
NLB static IPsAssign a floating IP to the reverse proxy instance and communicate the new address to downstream IP-allowlisting partners.
EKS/ECS network integrationAWS container networking uses VPC CNI (pod IPs from VPC CIDR). Kubernetes on Quake AI uses flannel/Calico/OVN-Kubernetes CNI as an overlay on Neutron networks.
Security Group limitsAWS defaults to 5 security groups per network interface, adjustable to a maximum of 16. On Neutron, the security-groups-per-port limit is set by the operator; confirm the value for your project before migrating.

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.

For the full policy, see Usage Guidelines.

Last validated: 22.06.2026

Was this page helpful?