# Migrate from DigitalOcean VPC to Quake AI

Source: https://docs.quake.ai/docs/network/migration/migrate-from-do-vpc
Markdown: https://docs.quake.ai/docs/network/migration/migrate-from-do-vpc.md

---

# Migrate from DigitalOcean VPC to Quake AI

DigitalOcean's networking model is among the simplest of the major cloud providers and maps most cleanly to Quake AI's [OpenStack Neutron](/resources/migration/openstack). Cloud Firewalls are stateful and allow-only (matching Neutron security groups), Reserved IPs are semantically identical to floating IPs, and private VPC networking maps directly to Neutron networks and subnets. The primary challenges are DNS recreation and the shift from DigitalOcean's tag-based firewall targeting to Neutron's security group per-port assignment.

## Service mapping

<MigrationTable provider="do" service="network" />


## Prerequisites

- A Quake AI account with [application credentials](/docs/tools/generate-app-credentials)
- The [OpenStack CLI](/docs/tools/install-openstack-client) installed and configured
- An inventory of your DigitalOcean resources: VPCs, Cloud Firewalls, Reserved IPs, Load Balancers, and DNS zones
- An SSH key pair imported to Quake AI (`openstack keypair create --public-key`)

## Topology mapping

DigitalOcean's flat VPC model maps almost 1:1 to Neutron. The main structural difference is that Droplets have both a public and private interface by default, while Quake AI's PublicStatic model uses a private interface plus a separately allocated floating IP.

<Figure caption="DigitalOcean VPC with Droplets, Cloud Firewalls, and Reserved IPs maps to a Neutron network with router, floating IPs, and security groups">

```d2
direction: down

do: DigitalOcean VPC {
  droplet: Droplet
  public_nic: Public NIC
  private_nic: Private NIC
  cloud_fw: Cloud Firewall
  reserved_ip: Reserved IP
  droplet -> public_nic
  droplet -> private_nic
  cloud_fw -> droplet: tag-based
  reserved_ip -> public_nic
}

neutron: Quake AI Neutron {
  network: Tenant Network
  subnet: Subnet
  router: Router (SNAT)
  fip: Floating IP
  sg: Security Group
  port: Port
  network -> subnet
  router -> network
  port -> network
  sg -> port: port-level
  fip -> port
}

do -> neutron: maps to
```

</Figure>

| DigitalOcean concept | Neutron equivalent | Notes |
|---|---|---|
| VPC | Network + Subnet | DO VPC is flat L3; Neutron adds explicit subnet and router |
| Datacenter region | Region | Direct mapping |
| Public IP (primary) | PublicEphemeral model or floating IP | Ephemeral on rebuild unless Reserved IP used |
| Reserved IP | Floating IP | Same operating model: static, reassignable, region-scoped |
| NAT Gateway | Router (SNAT) | Router provides SNAT by default; no separate object or per-node charge |
| Cloud Firewall | Security Group | Allow-only, stateful; similar model |
| Droplet tag-based firewall | Security Group applied to multiple ports | Tags group Droplets; SGs group ports |
| Load Balancer | Self-managed reverse proxy or external edge | Feature comparison below |
| VPC Peering | **No equivalent** | No network peering on Quake AI |

### Set up the Neutron equivalent

```bash
openstack network create my-network

openstack subnet create my-subnet \
  --network my-network \
  --subnet-range 192.168.0.0/24 \
  --gateway 192.168.0.1 \
  --dns-nameserver 8.8.8.8

openstack router create my-router
openstack router set my-router --external-gateway PublicStatic
openstack router add subnet my-router my-subnet
```

## Security rule translation

DigitalOcean Cloud Firewalls and Neutron security groups share the same core model: stateful, allow-only, deny-all inbound by default, allow-all outbound by default.

| Dimension | DigitalOcean Cloud Firewall | Neutron Security Group |
|---|---|---|
| Enforcement level | Droplet or tag | Port |
| Statefulness | Stateful | Stateful |
| Rule model | Allow-only | Allow-only |
| Inbound default | Deny-all | Deny-all |
| Outbound default | Allow-all | Allow-all |
| Source types | CIDR, Droplet IDs, tags, Load Balancers | CIDR, Security Group ID |

The key vocabulary difference: DigitalOcean uses **tags** to group Droplets for firewall targeting. Neutron uses **security group references** (`--remote-group`). Both produce functionally identical inter-tier allow rules.

### 3-tier app example

**DigitalOcean source:**
- `fw-web`: inbound TCP 80, 443 from any
- `fw-app`: inbound TCP 8080 from tag `web-tier`
- `fw-db`: inbound TCP 5432 from tag `app-tier`

**Neutron target:**

```bash
openstack security group create sg-web
openstack security group rule create sg-web \
  --protocol tcp --dst-port 80 --remote-ip 0.0.0.0/0 --ingress
openstack security group rule create sg-web \
  --protocol tcp --dst-port 443 --remote-ip 0.0.0.0/0 --ingress

openstack security group create sg-app
openstack security group rule create sg-app \
  --protocol tcp --dst-port 8080 --remote-group sg-web --ingress

openstack security group create sg-db
openstack security group rule create sg-db \
  --protocol tcp --dst-port 5432 --remote-group sg-app --ingress
```

Apply `sg-web` to all web tier ports, `sg-app` to all app tier ports, and `sg-db` to all database tier ports. This replaces the tag-based targeting with security group assignment.

## Load balancer migration

Replace a DigitalOcean Load Balancer with a reverse proxy such as HAProxy, Nginx, Caddy, Traefik, or Envoy. Assign a floating IP to the proxy instance and route requests to application instances over a private network.

The proxy can provide HTTP and TCP forwarding, health checks, sticky sessions, redirects, and Proxy Protocol. Use Certbot or Caddy for certificate issuance and renewal. Put an external CDN or WAF in front of the proxy when you need edge caching or managed request filtering.

## Floating IP setup

| DigitalOcean Reserved IP | Neutron Floating IP |
|---|---|
| Static, region-scoped public IPv4 | Static, region-scoped public IPv4 |
| Included in Droplet pricing when assigned; charged when idle. See [DigitalOcean pricing](https://www.digitalocean.com/pricing) for current rates. | Included in Quake AI pricing |
| Re-assignable across Droplets in same region | Re-assignable across ports in same region |
| One per resource at a time | One per port at a time |
| IPv6 supported (Reserved IPv6 IPs GA since 2024) | IPv6 not documented on Quake AI; DO Reserved IPv6 IPs have no Quake AI equivalent |

Allocate and associate a floating IP:

```bash
openstack floating ip create PublicStatic
openstack server add floating ip MY_INSTANCE FLOATING_IP_ADDRESS
```

DigitalOcean renamed "Floating IPs" to "Reserved IPs" in 2022. Quake AI and OpenStack use the original "Floating IP" terminology.

## DNS cutover

DigitalOcean provides a free managed DNS service. Quake AI has no managed DNS. Migrate your zones to an external provider.

1. **Export zone file**: From the DigitalOcean Control Panel, go to **Networking** > **Domains** > **Download zone**. This downloads a standard BIND zone file.
2. **Lower TTLs**: Set all record TTLs to 300 seconds at DigitalOcean; wait for the current TTL period to expire.
3. **Import at new provider**: Most DNS providers (Cloudflare, NS1, Route 53) accept BIND zone file imports.
4. **Validate**: `dig @NEW_NAMESERVER example.com A`
5. **Update registrar NS records**: Point to new nameservers.
6. **Monitor for 48 hours**: Keep DigitalOcean DNS active during monitoring; revert via registrar if issues arise.
7. **Restore TTLs**: Raise to 3600+ after successful cutover.

## Validation checklist

- [ ] Neutron network, subnet, and router are operational
- [ ] Security group rules match your Cloud Firewall rules (compare port/CIDR combinations)
- [ ] Tag-based firewall groups are replaced by security group assignments on the correct ports
- [ ] Floating IPs are associated with the correct instance ports
- [ ] Reverse proxy health checks pass for application backends
- [ ] TLS termination and renewal work on the proxy or external edge
- [ ] DNS records resolve to the proxy floating IP or external edge hostname
- [ ] Applications respond correctly through the full network path

## Provider-specific gotchas

| Topic | Detail |
|---|---|
| Bandwidth model shift | DO Droplets include a per-month pooled bandwidth allowance with per-GiB overage. Quake AI includes bandwidth in flavor pricing with no per-GB charge. See [DigitalOcean pricing](https://www.digitalocean.com/pricing). |
| No tag-based grouping | DO tags dynamically group Droplets for firewall targeting. Neutron requires explicit per-port security group assignment. Use Terraform or Ansible to make this declarative. |
| NAT Gateway cost | DigitalOcean NAT Gateway (GA as of 2024) is a separate billable resource. Neutron Router provides SNAT at no additional cost. See [DigitalOcean pricing](https://www.digitalocean.com/pricing) for current rates. |
| No VPC Peering | DigitalOcean VPC Peering (GA since 2024) supports free intra-datacenter peering and metered inter-datacenter peering, with up to 50 peering connections per account. Quake AI has no equivalent; use VPN overlay for cross-network communication. See [DigitalOcean VPC pricing](https://www.digitalocean.com/pricing) for current rates. |

## See also

- [Migrating from DigitalOcean to Quake AI](/resources/migration/from-digitalocean): full cross-service migration hub
- [Migrate from Droplets to Quake AI Compute](/docs/compute/migration/migrate-from-droplets): compute workload migration
- [Network migration guides](/docs/network/migration): all provider guides
- [Create a security group](/docs/network/how-to/create-security-group): Neutron security group setup
