Skip to content

Network Service CLI Reference

Reference · Updated Sep 2026

Coming from another cloud?

▸AWS·Amazon Virtual Private Cloud

Amazon Virtual Private Cloudhigh

  • AWS VPC is regional with CIDR /16-/28.
  • OpenStack Networks project-scoped L2 with flexible CIDR.
  • AWS requires IGW for public.
  • OpenStack provider nets or floating IPs.
AWS docs ↗
▸Azure·Virtual Network (VNet)

Virtual Network (VNet)high

  • Azure VNets are strictly regional Layer 3 overlays scoped to one subscription with no L2 VLAN support ().
  • VNets and subnets creation free, but subnets min /29 with Azure reserving 5 IPs per subnet ().
  • Managed via ARM REST APIs/PowerShell/CLI vs Neutron REST API.
  • Isolated per subscription; peering for cross-VNet connectivity vs OpenStack project networks connected via routers.
Azure docs ↗
▸DigitalOcean·VPC (VPC Network)

VPC (VPC Network)high

  • Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
  • Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
  • NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
  • Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
DigitalOcean docs ↗
▸Google Cloud·VPC Network

VPC Networkhigh

  • GCP VPC is global (spans all regions) whereas OpenStack Neutron networks are project-scoped and region-local.
  • GCP uses shared VPC for cross-project networking (requires org-level config); OpenStack uses shared networks via admin.
  • Subnets in GCP are regional, auto-mode creates one per region automatically; OpenStack requires explicit subnet creation.
  • GCP VPC Flow Logs per-subnet; OpenStack has no native equivalent without external tools.
Google Cloud docs ↗
▸Hetzner·Networks

Networkshigh

  • Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs.
  • CCM supports route controller for pod networking when enabled; no native provider networks like OpenStack.
  • Limited to Hetzner regions, IPv4 only for private (IPv6 public).
  • Networks are free with no usage charges, unlike potential metering in OpenStack clouds ().
Hetzner docs ↗

Network service CLI reference

The Network CLI reference lists curated commands with Quake AI-specific context. This page covers core resource commands; router static routes and security-group commands are documented on that reference.

See the OpenStack command-line client reference for the full list of openstack commands.

These commands manage networks, subnets, ports, routers, and floating IPs in your OpenStack environment. NETWORK_ID_OR_NAME, SUBNET_ID_OR_NAME, PORT_ID_OR_NAME, ROUTER_ID_OR_NAME, and FLOATING_IP_ID_OR_ADDRESS are placeholders that you replace with the actual IDs or names of the resources.

List networks#

bash
openstack network list

Show network details#

bash
openstack network show NETWORK_ID_OR_NAME

Create a network#

bash
openstack network create NETWORK_NAME

Delete a network#

bash
openstack network delete NETWORK_ID_OR_NAME

List subnets#

bash
openstack subnet list

Show subnet details#

bash
openstack subnet show SUBNET_ID_OR_NAME

Create a subnet#

bash
openstack subnet create --network NETWORK_ID_OR_NAME --subnet-range CIDR SUBNET_NAME
  • CIDR: The IP address range of the subnet in CIDR notation (for example, 192.168.1.0/24).

Delete a subnet#

bash
openstack subnet delete SUBNET_ID_OR_NAME

List ports#

bash
openstack port list

Show port details#

bash
openstack port show PORT_ID_OR_NAME

Create a port#

bash
openstack port create --network NETWORK_ID_OR_NAME PORT_NAME

Delete a port#

bash
openstack port delete PORT_ID_OR_NAME

List routers#

bash
openstack router list

Show router details#

bash
openstack router show ROUTER_ID_OR_NAME

Create a router#

bash
openstack router create ROUTER_NAME

To set the external gateway when you create the router, pass --external-gateway:

bash
openstack router create --external-gateway PUBLIC_NETWORK_ID_OR_NAME ROUTER_NAME

Delete a router#

bash
openstack router delete ROUTER_ID_OR_NAME

Add a router interface#

bash
openstack router add subnet ROUTER_ID_OR_NAME SUBNET_ID_OR_NAME

Remove a router interface#

bash
openstack router remove subnet ROUTER_ID_OR_NAME SUBNET_ID_OR_NAME

Set a router external gateway#

bash
openstack router set --external-gateway PUBLIC_NETWORK_ID_OR_NAME ROUTER_ID_OR_NAME

A port on a router's internal subnet cannot have a floating IP associated until the router has an external gateway. The external network must be one that is marked router:external (on Quake AI, PublicStatic).

Remove a router external gateway#

bash
openstack router unset --external-gateway ROUTER_ID_OR_NAME

List external networks#

bash
openstack network list --external

Only the networks returned here (those with router:external = true) can serve as a router external gateway or as the source network for a floating IP.

List floating IPs#

bash
openstack floating ip list

Create a floating IP#

bash
openstack floating ip create PUBLIC_NETWORK_ID_OR_NAME

Associate a floating IP with a port#

bash
openstack floating ip set --port PORT_ID_OR_NAME FLOATING_IP_ID_OR_ADDRESS

If the port's subnet is not connected to a router with an external gateway, this returns 404 NotFoundException, reporting that the external network is not reachable from the subnet. Set the router external gateway first. The status code is 404, not the 400 or 409 a binding conflict might suggest.

Disassociate a floating IP#

bash
openstack floating ip unset --port FLOATING_IP_ID_OR_ADDRESS

Output columns#

Select specific columns with --column COL1 --column COL2 or change the output format with -f json, -f csv, or -f table (default).

openstack network list#

ColumnDescription
IDNetwork UUID
NameNetwork name
SubnetsAssociated subnet UUIDs

openstack subnet list#

ColumnDescription
IDSubnet UUID
NameSubnet name
NetworkParent network UUID
SubnetCIDR range (e.g., 192.168.0.0/24)

openstack router list#

ColumnDescription
IDRouter UUID
NameRouter name
StatusCurrent state (ACTIVE, ERROR)
StateAdministrative state (UP, DOWN)
ProjectOwning project ID

openstack port list#

ColumnDescription
IDPort UUID
NamePort name
MAC AddressLayer 2 hardware address
Fixed IP AddressesAssigned IP addresses and subnet IDs
StatusCurrent state (ACTIVE, DOWN, BUILD)

openstack floating ip list#

ColumnDescription
IDFloating IP UUID
Floating IP AddressPublic IP address
Fixed IP AddressAssociated private IP (empty if unassociated)
PortAssociated port UUID (empty if unassociated)
Floating NetworkSource external network UUID
ProjectOwning project ID
Was this page helpful?