Skip to content

Migrate from DigitalOcean VPC to Quake AI

Migration · Updated Jun 2026

Coming from another cloud?

▸DigitalOcean·VPC (VPC Network), Cloud Firewalls, Load Balancers (Regional Load Balancers and Global Load Balancers), DNS

VPC (VPC Network)high

  • Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
  • Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
  • NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
  • Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
DigitalOcean docs ↗

Cloud Firewallshigh

  • Applied to Droplets via droplet_ids and/or tags; Neutron security groups attach to ports.
  • Both inbound and outbound rules; default deny all if no rules configured.
  • Free service like Neutron security groups; no implicit L4 stateful rules without explicit config.
DigitalOcean docs ↗

Load Balancers (Regional Load Balancers and Global Load Balancers)high

  • Product shape: DigitalOcean provides regional and global managed load balancers. Quake AI workloads use a self-managed reverse proxy, CDN/WAF edge, or Kubernetes LoadBalancer Service.
  • DigitalOcean can select backend Droplets by explicit list or by tag. Self-managed Quake AI edges select backends through proxy or ingress configuration.
  • VPC connectivity behavior: the load balancer automatically connects to Droplets in its VPC network and falls back to public IP if private networking is disabled. Self-managed Quake AI edges route to backends through proxy configuration.
  • DigitalOcean documents built-in Let’s Encrypt certificate management, optional PROXY protocol v1, and regional HTTP/3 support. On Quake AI, configure these features on the selected self-managed edge.
DigitalOcean docs ↗

Migrate from DigitalOcean VPC to Quake AI

DigitalOcean's networking model is among the simplest of the major cloud providers and maps most cleanly to Quake AI's OpenStack Neutron. Cloud Firewalls are stateful and allow-only (matching Neutron security groups), Reserved IPs are semantically identical to floating IPs, and private VPC networking maps directly to Neutron networks and subnets. The primary challenges are DNS recreation and the shift from DigitalOcean's tag-based firewall targeting to Neutron's security group per-port assignment.

Service mapping#

DigitalOcean to Quake AI

DigitalOcean serviceQuake AI equivalentKey difference
Reserved IPs (formerly Floating IPs)Floating IPsNaming/API surface: DigitalOcean renamed Floating IPs to Reserved IPs; endpoints and fields change from `floating_ips` to `reserved_ips`... see details
VPC NAT Gateway (outbound-only, GA November 2025)NATDO VPC NAT Gateway (POST /v2/vpc_nat_gateways) provides outbound internet egress (SNAT) for private Droplets only; it does not support... see details
Load Balancers (Regional Load Balancers and Global Load Balancers)NetworkProduct shape: DigitalOcean provides regional and global managed load balancers. Quake AI workloads use a self-managed reverse proxy,... see details
VPC-native Networking with CiliumNetworkingVPC-native using Cilium eBPF (K8s 1.31+), Gateway API default on 1.33+; Quake AI Kubernetes clusters use CNI plugins (Flannel, Calico,... see details
VPC (VPC Network)NetworksRegion-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas... see details
N/A (No port resource — network interfaces are implicit per Droplet)PortsDigitalOcean has no port concept. Droplets receive a private VPC IP automatically on creation; the network interface is implicit and not... see details
N/A (No router resource — VPC NAT Gateway for egress only; no inter-VPC routing)RoutersDigitalOcean has no managed router resource. The VPC NAT Gateway (GA November 2025) handles outbound internet egress for private Droplets;... see details
SecuritySecurityNo notable divergence
Cloud FirewallsSecurity GroupsApplication model: DigitalOcean firewalls are applied to Droplets via `droplet_ids` and/or tags, whereas OpenStack security groups are... see details
Cloud FirewallsSecurity GroupsApplied to Droplets via droplet_ids and/or tags; Neutron security groups attach to ports. Both inbound and outbound rules; default deny all... see details
N/A (No manual subnet management — VPC handles IP assignment automatically)SubnetsDigitalOcean VPCs automatically manage an internal IP range; users cannot create, delete, or resize subnets. Neutron subnets are explicitly... see details

Prerequisites#

  • A Quake AI account with application credentials
  • The OpenStack CLI installed and configured
  • An inventory of your DigitalOcean resources: VPCs, Cloud Firewalls, Reserved IPs, Load Balancers, and DNS zones
  • An SSH key pair imported to Quake AI (openstack keypair create --public-key)

Topology mapping#

DigitalOcean's flat VPC model maps almost 1:1 to Neutron. The main structural difference is that Droplets have both a public and private interface by default, while Quake AI's PublicStatic model uses a private interface plus a separately allocated floating IP.

DigitalOcean VPCQuake AI NeutronDropletPublic NICPrivate NICCloud FirewallReserved IPTenant NetworkSubnetRouter (SNAT)Floating IPSecurity GroupPort tag-basedport-levelmaps to
Click to zoom
DigitalOcean VPC with Droplets, Cloud Firewalls, and Reserved IPs maps to a Neutron network with router, floating IPs, and security groups
DigitalOcean conceptNeutron equivalentNotes
VPCNetwork + SubnetDO VPC is flat L3; Neutron adds explicit subnet and router
Datacenter regionRegionDirect mapping
Public IP (primary)PublicEphemeral model or floating IPEphemeral on rebuild unless Reserved IP used
Reserved IPFloating IPSame operating model: static, reassignable, region-scoped
NAT GatewayRouter (SNAT)Router provides SNAT by default; no separate object or per-node charge
Cloud FirewallSecurity GroupAllow-only, stateful; similar model
Droplet tag-based firewallSecurity Group applied to multiple portsTags group Droplets; SGs group ports
Load BalancerSelf-managed reverse proxy or external edgeFeature comparison below
VPC PeeringNo equivalentNo network peering on Quake AI

Set up the Neutron equivalent#

bash
openstack network create my-network

openstack subnet create my-subnet \
  --network my-network \
  --subnet-range 192.168.0.0/24 \
  --gateway 192.168.0.1 \
  --dns-nameserver 8.8.8.8

openstack router create my-router
openstack router set my-router --external-gateway PublicStatic
openstack router add subnet my-router my-subnet

Security rule translation#

DigitalOcean Cloud Firewalls and Neutron security groups share the same core model: stateful, allow-only, deny-all inbound by default, allow-all outbound by default.

DimensionDigitalOcean Cloud FirewallNeutron Security Group
Enforcement levelDroplet or tagPort
StatefulnessStatefulStateful
Rule modelAllow-onlyAllow-only
Inbound defaultDeny-allDeny-all
Outbound defaultAllow-allAllow-all
Source typesCIDR, Droplet IDs, tags, Load BalancersCIDR, Security Group ID

The key vocabulary difference: DigitalOcean uses tags to group Droplets for firewall targeting. Neutron uses security group references (--remote-group). Both produce functionally identical inter-tier allow rules.

3-tier app example#

DigitalOcean source:

  • fw-web: inbound TCP 80, 443 from any
  • fw-app: inbound TCP 8080 from tag web-tier
  • fw-db: inbound TCP 5432 from tag app-tier

Neutron target:

bash
openstack security group create sg-web
openstack security group rule create sg-web \
  --protocol tcp --dst-port 80 --remote-ip 0.0.0.0/0 --ingress
openstack security group rule create sg-web \
  --protocol tcp --dst-port 443 --remote-ip 0.0.0.0/0 --ingress

openstack security group create sg-app
openstack security group rule create sg-app \
  --protocol tcp --dst-port 8080 --remote-group sg-web --ingress

openstack security group create sg-db
openstack security group rule create sg-db \
  --protocol tcp --dst-port 5432 --remote-group sg-app --ingress

Apply sg-web to all web tier ports, sg-app to all app tier ports, and sg-db to all database tier ports. This replaces the tag-based targeting with security group assignment.

Load balancer migration#

Replace a DigitalOcean Load Balancer with a reverse proxy such as HAProxy, Nginx, Caddy, Traefik, or Envoy. Assign a floating IP to the proxy instance and route requests to application instances over a private network.

The proxy can provide HTTP and TCP forwarding, health checks, sticky sessions, redirects, and Proxy Protocol. Use Certbot or Caddy for certificate issuance and renewal. Put an external CDN or WAF in front of the proxy when you need edge caching or managed request filtering.

Floating IP setup#

DigitalOcean Reserved IPNeutron Floating IP
Static, region-scoped public IPv4Static, region-scoped public IPv4
Included in Droplet pricing when assigned; charged when idle. See DigitalOcean pricing for current rates.Included in Quake AI pricing
Re-assignable across Droplets in same regionRe-assignable across ports in same region
One per resource at a timeOne per port at a time
IPv6 supported (Reserved IPv6 IPs GA since 2024)IPv6 not documented on Quake AI; DO Reserved IPv6 IPs have no Quake AI equivalent

Allocate and associate a floating IP:

bash
openstack floating ip create PublicStatic
openstack server add floating ip MY_INSTANCE FLOATING_IP_ADDRESS

DigitalOcean renamed "Floating IPs" to "Reserved IPs" in 2022. Quake AI and OpenStack use the original "Floating IP" terminology.

DNS cutover#

DigitalOcean provides a free managed DNS service. Quake AI has no managed DNS. Migrate your zones to an external provider.

  1. Export zone file: From the DigitalOcean Control Panel, go to Networking > Domains > Download zone. This downloads a standard BIND zone file.
  2. Lower TTLs: Set all record TTLs to 300 seconds at DigitalOcean; wait for the current TTL period to expire.
  3. Import at new provider: Most DNS providers (Cloudflare, NS1, Route 53) accept BIND zone file imports.
  4. Validate: dig @NEW_NAMESERVER example.com A
  5. Update registrar NS records: Point to new nameservers.
  6. Monitor for 48 hours: Keep DigitalOcean DNS active during monitoring; revert via registrar if issues arise.
  7. Restore TTLs: Raise to 3600+ after successful cutover.

Validation checklist#

  • Neutron network, subnet, and router are operational
  • Security group rules match your Cloud Firewall rules (compare port/CIDR combinations)
  • Tag-based firewall groups are replaced by security group assignments on the correct ports
  • Floating IPs are associated with the correct instance ports
  • Reverse proxy health checks pass for application backends
  • TLS termination and renewal work on the proxy or external edge
  • DNS records resolve to the proxy floating IP or external edge hostname
  • Applications respond correctly through the full network path

Provider-specific gotchas#

TopicDetail
Bandwidth model shiftDO Droplets include a per-month pooled bandwidth allowance with per-GiB overage. Quake AI includes bandwidth in flavor pricing with no per-GB charge. See DigitalOcean pricing.
No tag-based groupingDO tags dynamically group Droplets for firewall targeting. Neutron requires explicit per-port security group assignment. Use Terraform or Ansible to make this declarative.
NAT Gateway costDigitalOcean NAT Gateway (GA as of 2024) is a separate billable resource. Neutron Router provides SNAT at no additional cost. See DigitalOcean pricing for current rates.
No VPC PeeringDigitalOcean VPC Peering (GA since 2024) supports free intra-datacenter peering and metered inter-datacenter peering, with up to 50 peering connections per account. Quake AI has no equivalent; use VPN overlay for cross-network communication. See DigitalOcean VPC pricing for current rates.

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.

For the full policy, see Usage Guidelines.

Last validated: 22.06.2026

Was this page helpful?