Skip to content

Security Groups Console

Reference · Updated Sep 2026

Coming from another cloud?

▸AWS·Amazon VPC + VPC CNI

Amazon VPC + VPC CNIhigh

  • Quake AI uses per-cluster private networks and routers for Kubernetes; EKS uses a customer VPC with ENI pod networking.
  • Quake AI K8s uses Flannel/Calico/Cilium CNI on Neutron; EKS uses VPC CNI with prefix delegation.
  • EKS bills cross-AZ control traffic; OpenStack no.
AWS docs ↗
▸Azure·AKS Networking

AKS Networkinghigh

  • Azure CNI or kubenet, integrates Azure Load Balancer/Application Gateway; Quake AI Kubernetes clusters use Neutron private networks and routers with CNI plugins (Flannel, Calico, Cilium).
  • Bring-your-own CNI supported; Quake AI tenant-isolated Neutron.
  • Azure-specific: Application routing add-on (nginx), no native Neutron.
Azure docs ↗
▸DigitalOcean·VPC-native Networking with Cilium

VPC-native Networking with Ciliumhigh

  • VPC-native using Cilium eBPF (K8s 1.31+), Gateway API default on 1.33+; Quake AI Kubernetes clusters use CNI plugins (Flannel, Calico, Cilium) on Neutron private networks.
  • Direct pod-to-VPC resource routing and internal load balancers; Quake AI Kubernetes clusters expose services through Kubernetes LoadBalancer behavior and floating IPs.
DigitalOcean docs ↗
▸Google Cloud·VPC Networking

VPC Networkinghigh

  • Per-cluster Neutron networks + floating IPs; GKE shared VPC with alias IP ranges.
  • Kubernetes LoadBalancer behavior replaces Google Cloud Load Balancers after migration.
Google Cloud docs ↗
▸Hetzner·Networks

Networkshigh

  • Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs.
  • CCM supports route controller for pod networking when enabled; no native provider networks like OpenStack.
  • Limited to Hetzner regions, IPv4 only for private (IPv6 public).
  • Networks are free with no usage charges, unlike potential metering in OpenStack clouds ().
Hetzner docs ↗

Security groups console

Overview#

Security groups provide a flexible mechanism for securing virtual machine instances by controlling the flow of network traffic. They are an essential component of network security in a cloud environment, enabling you to define and enforce security policies that meet your requirements.

Select Network > Security Groups to view the security groups console. The list view shows all security groups in the project with their name, description, and associated rules count.

Security Groups console listing security groups with columns for name, description, and actionsClick to zoom
Security groups list showing project security groups

You can view, edit, and delete security groups. You add and delete rules to and from a security group. You can specify the remote source with an IP address block or a security group, and a port or port range for each rule.

Select a security group to view its rules and configuration.

Security group detail view showing the group name, description, and a table of ingress rules with protocol, port range, remote source, and direction columnsClick to zoom
Security group detail showing inbound rules for SSH and HTTP traffic

To create a new security group, select Create Security Group, provide a name and description, then add rules.

Create Security Group dialog with name and description fields filled inClick to zoom
Create Security Group dialog
Create Security Group Rule dialog showing protocol selection, port range, direction, and remote source fieldsClick to zoom
Adding a rule to a security group

Security groups#

Security groups CLI reference#

Security groups API reference#

See also#

Was this page helpful?