Migrate from DigitalOcean VPC to Quake AI
Coming from another cloud?
▸DigitalOcean·VPC (VPC Network), Cloud Firewalls, Load Balancers (Regional Load Balancers and Global Load Balancers), DNS
VPC (VPC Network)
- Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
- Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
- NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
- Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
Cloud Firewalls
- Applied to Droplets via droplet_ids and/or tags; Neutron security groups attach to ports.
- Both inbound and outbound rules; default deny all if no rules configured.
- Free service like Neutron security groups; no implicit L4 stateful rules without explicit config.
Load Balancers (Regional Load Balancers and Global Load Balancers)
- Product shape: DigitalOcean provides regional and global managed load balancers. Quake AI workloads use a self-managed reverse proxy, CDN/WAF edge, or Kubernetes LoadBalancer Service.
- DigitalOcean can select backend Droplets by explicit list or by tag. Self-managed Quake AI edges select backends through proxy or ingress configuration.
- VPC connectivity behavior: the load balancer automatically connects to Droplets in its VPC network and falls back to public IP if private networking is disabled. Self-managed Quake AI edges route to backends through proxy configuration.
- DigitalOcean documents built-in Let’s Encrypt certificate management, optional PROXY protocol v1, and regional HTTP/3 support. On Quake AI, configure these features on the selected self-managed edge.
Migrate from DigitalOcean VPC to Quake AI
DigitalOcean's networking model is among the simplest of the major cloud providers and maps most cleanly to Quake AI's OpenStack Neutron. Cloud Firewalls are stateful and allow-only (matching Neutron security groups), Reserved IPs are semantically identical to floating IPs, and private VPC networking maps directly to Neutron networks and subnets. The primary challenges are DNS recreation and the shift from DigitalOcean's tag-based firewall targeting to Neutron's security group per-port assignment.
Service mapping#
DigitalOcean to Quake AI
| DigitalOcean service | Quake AI equivalent | Key difference |
|---|---|---|
| Reserved IPs (formerly Floating IPs) | Floating IPs | Naming/API surface: DigitalOcean renamed Floating IPs to Reserved IPs; endpoints and fields change from `floating_ips` to `reserved_ips`... see details |
| VPC NAT Gateway (outbound-only, GA November 2025) | NAT | DO VPC NAT Gateway (POST /v2/vpc_nat_gateways) provides outbound internet egress (SNAT) for private Droplets only; it does not support... see details |
| Load Balancers (Regional Load Balancers and Global Load Balancers) | Network | Product shape: DigitalOcean provides regional and global managed load balancers. Quake AI workloads use a self-managed reverse proxy,... see details |
| VPC-native Networking with Cilium | Networking | VPC-native using Cilium eBPF (K8s 1.31+), Gateway API default on 1.33+; Quake AI Kubernetes clusters use CNI plugins (Flannel, Calico,... see details |
| VPC (VPC Network) | Networks | Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas... see details |
| N/A (No port resource — network interfaces are implicit per Droplet) | Ports | DigitalOcean has no port concept. Droplets receive a private VPC IP automatically on creation; the network interface is implicit and not... see details |
| N/A (No router resource — VPC NAT Gateway for egress only; no inter-VPC routing) | Routers | DigitalOcean has no managed router resource. The VPC NAT Gateway (GA November 2025) handles outbound internet egress for private Droplets;... see details |
| Security | Security | No notable divergence |
| Cloud Firewalls | Security Groups | Application model: DigitalOcean firewalls are applied to Droplets via `droplet_ids` and/or tags, whereas OpenStack security groups are... see details |
| Cloud Firewalls | Security Groups | Applied to Droplets via droplet_ids and/or tags; Neutron security groups attach to ports. Both inbound and outbound rules; default deny all... see details |
| N/A (No manual subnet management — VPC handles IP assignment automatically) | Subnets | DigitalOcean VPCs automatically manage an internal IP range; users cannot create, delete, or resize subnets. Neutron subnets are explicitly... see details |
Prerequisites#
- A Quake AI account with application credentials
- The OpenStack CLI installed and configured
- An inventory of your DigitalOcean resources: VPCs, Cloud Firewalls, Reserved IPs, Load Balancers, and DNS zones
- An SSH key pair imported to Quake AI (
openstack keypair create --public-key)
Topology mapping#
DigitalOcean's flat VPC model maps almost 1:1 to Neutron. The main structural difference is that Droplets have both a public and private interface by default, while Quake AI's PublicStatic model uses a private interface plus a separately allocated floating IP.
| DigitalOcean concept | Neutron equivalent | Notes |
|---|---|---|
| VPC | Network + Subnet | DO VPC is flat L3; Neutron adds explicit subnet and router |
| Datacenter region | Region | Direct mapping |
| Public IP (primary) | PublicEphemeral model or floating IP | Ephemeral on rebuild unless Reserved IP used |
| Reserved IP | Floating IP | Same operating model: static, reassignable, region-scoped |
| NAT Gateway | Router (SNAT) | Router provides SNAT by default; no separate object or per-node charge |
| Cloud Firewall | Security Group | Allow-only, stateful; similar model |
| Droplet tag-based firewall | Security Group applied to multiple ports | Tags group Droplets; SGs group ports |
| Load Balancer | Self-managed reverse proxy or external edge | Feature comparison below |
| VPC Peering | No equivalent | No network peering on Quake AI |
Set up the Neutron equivalent#
openstack network create my-network
openstack subnet create my-subnet \
--network my-network \
--subnet-range 192.168.0.0/24 \
--gateway 192.168.0.1 \
--dns-nameserver 8.8.8.8
openstack router create my-router
openstack router set my-router --external-gateway PublicStatic
openstack router add subnet my-router my-subnetSecurity rule translation#
DigitalOcean Cloud Firewalls and Neutron security groups share the same core model: stateful, allow-only, deny-all inbound by default, allow-all outbound by default.
| Dimension | DigitalOcean Cloud Firewall | Neutron Security Group |
|---|---|---|
| Enforcement level | Droplet or tag | Port |
| Statefulness | Stateful | Stateful |
| Rule model | Allow-only | Allow-only |
| Inbound default | Deny-all | Deny-all |
| Outbound default | Allow-all | Allow-all |
| Source types | CIDR, Droplet IDs, tags, Load Balancers | CIDR, Security Group ID |
The key vocabulary difference: DigitalOcean uses tags to group Droplets for firewall targeting. Neutron uses security group references (--remote-group). Both produce functionally identical inter-tier allow rules.
3-tier app example#
DigitalOcean source:
fw-web: inbound TCP 80, 443 from anyfw-app: inbound TCP 8080 from tagweb-tierfw-db: inbound TCP 5432 from tagapp-tier
Neutron target:
openstack security group create sg-web
openstack security group rule create sg-web \
--protocol tcp --dst-port 80 --remote-ip 0.0.0.0/0 --ingress
openstack security group rule create sg-web \
--protocol tcp --dst-port 443 --remote-ip 0.0.0.0/0 --ingress
openstack security group create sg-app
openstack security group rule create sg-app \
--protocol tcp --dst-port 8080 --remote-group sg-web --ingress
openstack security group create sg-db
openstack security group rule create sg-db \
--protocol tcp --dst-port 5432 --remote-group sg-app --ingressApply sg-web to all web tier ports, sg-app to all app tier ports, and sg-db to all database tier ports. This replaces the tag-based targeting with security group assignment.
Load balancer migration#
Replace a DigitalOcean Load Balancer with a reverse proxy such as HAProxy, Nginx, Caddy, Traefik, or Envoy. Assign a floating IP to the proxy instance and route requests to application instances over a private network.
The proxy can provide HTTP and TCP forwarding, health checks, sticky sessions, redirects, and Proxy Protocol. Use Certbot or Caddy for certificate issuance and renewal. Put an external CDN or WAF in front of the proxy when you need edge caching or managed request filtering.
Floating IP setup#
| DigitalOcean Reserved IP | Neutron Floating IP |
|---|---|
| Static, region-scoped public IPv4 | Static, region-scoped public IPv4 |
| Included in Droplet pricing when assigned; charged when idle. See DigitalOcean pricing | Included in Quake AI pricing |
| Re-assignable across Droplets in same region | Re-assignable across ports in same region |
| One per resource at a time | One per port at a time |
| IPv6 supported (Reserved IPv6 IPs GA since 2024) | IPv6 not documented on Quake AI; DO Reserved IPv6 IPs have no Quake AI equivalent |
Allocate and associate a floating IP:
openstack floating ip create PublicStatic
openstack server add floating ip MY_INSTANCE FLOATING_IP_ADDRESSDigitalOcean renamed "Floating IPs" to "Reserved IPs" in 2022. Quake AI and OpenStack use the original "Floating IP" terminology.
DNS cutover#
DigitalOcean provides a free managed DNS service. Quake AI has no managed DNS. Migrate your zones to an external provider.
- Export zone file: From the DigitalOcean Control Panel, go to Networking > Domains > Download zone. This downloads a standard BIND zone file.
- Lower TTLs: Set all record TTLs to 300 seconds at DigitalOcean; wait for the current TTL period to expire.
- Import at new provider: Most DNS providers (Cloudflare, NS1, Route 53) accept BIND zone file imports.
- Validate:
dig @NEW_NAMESERVER example.com A - Update registrar NS records: Point to new nameservers.
- Monitor for 48 hours: Keep DigitalOcean DNS active during monitoring; revert via registrar if issues arise.
- Restore TTLs: Raise to 3600+ after successful cutover.
Validation checklist#
- Neutron network, subnet, and router are operational
- Security group rules match your Cloud Firewall rules (compare port/CIDR combinations)
- Tag-based firewall groups are replaced by security group assignments on the correct ports
- Floating IPs are associated with the correct instance ports
- Reverse proxy health checks pass for application backends
- TLS termination and renewal work on the proxy or external edge
- DNS records resolve to the proxy floating IP or external edge hostname
- Applications respond correctly through the full network path
Provider-specific gotchas#
| Topic | Detail |
|---|---|
| Bandwidth model shift | DO Droplets include a per-month pooled bandwidth allowance with per-GiB overage. Quake AI includes bandwidth in flavor pricing with no per-GB charge. See DigitalOcean pricing |
| No tag-based grouping | DO tags dynamically group Droplets for firewall targeting. Neutron requires explicit per-port security group assignment. Use Terraform or Ansible to make this declarative. |
| NAT Gateway cost | DigitalOcean NAT Gateway (GA as of 2024) is a separate billable resource. Neutron Router provides SNAT at no additional cost. See DigitalOcean pricing |
| No VPC Peering | DigitalOcean VPC Peering (GA since 2024) supports free intra-datacenter peering and metered inter-datacenter peering, with up to 50 peering connections per account. Quake AI has no equivalent; use VPN overlay for cross-network communication. See DigitalOcean VPC pricing |
See also#
- Migrating from DigitalOcean to Quake AI: full cross-service migration hub
- Migrate from Droplets to Quake AI Compute: compute workload migration
- Network migration guides: all provider guides
- Create a security group: Neutron security group setup
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.
For the full policy, see Usage Guidelines.
Last validated: 22.06.2026