Migration
Coming from another cloud?
▸AWS·Overview
This Quake AI feature maps to AWS’s Overview.
▸Azure·Overview
This Quake AI feature maps to Azure’s Overview.
▸DigitalOcean·Overview
This Quake AI feature maps to DigitalOcean’s Overview.
▸Google Cloud·Overview
This Quake AI feature maps to Google Cloud’s Overview.
▸Hetzner·Overview
This Quake AI feature maps to Hetzner’s Overview.
▸Linode·Overview
This Quake AI feature maps to Linode’s Overview.
▸Vultr·Overview
This Quake AI feature maps to Vultr’s Overview.
Migration
Evaluate Quake AI against your current provider, then move workloads. Quake AI runs on OpenStack, so every service below maps to a standard OpenStack project (Nova for compute, Neutron for networking, Cinder for block storage, Swift for object storage). Each provider entry below links to a concept-translation page that maps the services. The companion migration workflow (Migrate from {provider}) sits at the bottom of the concept page and in the sidebar.
Common migration workflow#
A typical provider migration follows six phases:
- Evaluate and plan. Read the concept-translation page for your provider. Identify which resources need to migrate: compute, object storage, block storage, networking, IaC templates, container workloads.
- Set up your Quake AI account. Create a project, generate application credentials, and install the OpenStack CLI. See the Quickstart.
- Migrate object storage. Object storage is typically the lowest-risk, highest-volume migration. Quake AI's S3-compatible API works with standard tools (rclone, aws-cli, s3cmd) once you swap the endpoint and credentials.
- Rewrite Infrastructure as Code. Translate provider-specific Terraform resources to the
openstackprovider. Terraform stacks port directly; ARM, Bicep, and CloudFormation get rewritten. - Provision compute and networking. Create instances, networks, subnets, routers, security groups, and floating IPs on Quake AI. The practical approach is to provision new instances and migrate application data, since cross-platform image compatibility (drivers, cloud-init configuration, kernel choices) is often imperfect even when image export is available.
- Validate and cut over. Verify applications respond correctly, point DNS at the new floating IPs, and confirm monitoring is in place before decommissioning source infrastructure.
By provider#
AWS
The largest concept-translation page on the platform. EC2 to Compute, S3 to Swift or the S3-compatible API, IAM to Keystone application credentials, VPC to Neutron. Includes a quick-reference mapping table, the IAM-to-application-credential model shift, and an OpenTofu example for the openstack provider.
Azure
Virtual Machines to Compute, Blob Storage to Swift, NSGs to security groups. Covers the NSG-to-security-group model shift (allow-only, no priority ordering, per-port binding), the Entra ID to application credentials change, and the AKS to Magnum trade-offs.
DigitalOcean
Droplets to instances, Spaces to Swift, VPC to Neutron. The move is lateral: same mental model, OpenStack APIs, and a fixed-monthly pricing model with no transfer caps.
GCP
Compute Engine to Compute, Cloud Storage to Swift, VPC firewall rules to Neutron security groups. The managed-services gap is the largest decision point.
Hetzner Cloud
Cloud Servers to Compute, Object Storage to Swift, abstract private networks to explicit Neutron networks, subnets, and routers. The networking model is the largest conceptual shift.
Linode (Akamai)
Linodes to Instances, Block Storage to Cinder, Object Storage to Swift, VPC and Cloud Firewall to explicit Neutron networks and security groups, NodeBalancers to self-managed edge proxies, and LKE to self-managed Kubernetes on Nova.
Vultr
Cloud Compute instances to Nova, Block Storage to Cinder, Object Storage to Swift, VPC 2.0 to explicit Neutron networks and subnets, Firewall Groups to security groups, Load Balancers to self-managed edge proxies, and VKE to self-managed Kubernetes on Nova.
The sidebar groups the concept-translation page and its companion Migrate from {provider} workflow together under each provider, so they read in order.
Service mapping#
Each table below lists the services or resource concepts on the source provider and links to the Quake AI documentation for the equivalent. The right-hand column carries the key divergence the migrating developer needs to plan for.
AWS to Quake AI
| AWS service | Quake AI equivalent | Key difference |
|---|---|---|
| Organizations | Account | AWS Organizations provides hierarchical OUs, SCPs for governance, consolidated billing; OpenStack lacks native multi-deployment orgs, uses... see details |
| IAM Users | Authentication | AWS IAM Users are tied exclusively to one AWS account with no native multi-account scoping without Organizations; OpenStack users exist in... see details |
| Stacks | Automation | Quake AI offers Heat (legacy OpenStack orchestration) and recommends OpenTofu for new IaC work; EKS uses declarative console/CLI. EKS Auto... see details |
| Billing and Cost Management | Billing | AWS has native consolidated billing via Organizations (single bill for all accounts); OpenStack has no standard billing service—usage... see details |
| N/A (No subscription concept — AWS Accounts with optional consolidated billing via AWS Organizations) | Billing | AWS has no subscription concept. Billing is per AWS Account. Multiple accounts can be grouped under AWS Organizations with consolidated... see details |
| Pay-As-You-Go (per-second billing, 60-second minimum for Linux EC2) | Billing | AWS bills EC2 Linux instances per second with a 60-second minimum. Pricing is not embedded in the Nova/flavor API; AWS instance pricing... see details |
| Amazon EBS Volume Copies (Clones) | Clones | Direct same-AZ copy only; requires source encrypted, size >= source; background initialization with instant low-latency access. One-time... see details |
| Amazon EC2 | Compute | No notable divergence |
| Server-Side Encryption | Encryption | SSE-C (customer keys, AES256) and SSE-OMK (Quake AI-managed AES256 per-object keys with root rotation). No SSE-S3 or SSE-KMS; SSE-OMK... see details |
| Instance Types | Flavors | Fixed predefined configurations only; no custom flavor creation. Extensive families for GPU/HPC/ARM etc. InstanceType as string param in... see details |
| Elastic IP addresses | Floating IPs | AWS charges idle EIPs. OpenStack floating IPs free/pool-limited. AWS regional instance/ENI. OpenStack project port. |
| Amazon Machine Images (AMIs) | Images | Managed via EC2 APIs, not Glance. Region-specific with cross-region copy. Marketplace AMIs may charge hourly fees. Includes block device... see details |
| EC2 Instances | Instances | Uses EC2 RunInstances API instead of Nova servers.create. Requires predefined instance type selection. Supports per-second On-Demand... see details |
| EC2 Key Pairs | Key Pairs | Public key auto-injected to authorized_keys at boot. Up to 5000 per region; AWS stores public key. Supports import of external keys... see details |
| Amazon EKS Cluster | Kubernetes | EKS control plane fully AWS-managed, single-tenant, across 3 AZs with auto scale/replace; on Quake AI you run the control plane on Nova... see details |
| NAT Gateway | NAT | AWS managed HA per AZ hourly/GB. OpenStack router SNAT L3 agent/OVN. OpenStack basic SNAT. OpenStack router-limited. |
| Elastic Load Balancing | Network | Quake AI workloads use a self-managed reverse proxy or Kubernetes LoadBalancer Service. AWS hourly/LCU billing. OpenStack VM billing. AWS... see details |
| Amazon VPC + VPC CNI | Networking | Quake AI uses per-cluster private networks and routers for Kubernetes; EKS uses a customer VPC with ENI pod networking. Quake AI K8s uses... see details |
| Amazon Virtual Private Cloud | Networks | AWS VPC is regional with CIDR /16-/28. OpenStack Networks project-scoped L2 with flexible CIDR. AWS requires IGW for public. OpenStack... see details |
| Access Control Lists (ACLs) | Object storage | Limited to basic public/private via console; advanced via S3 bucket policies (JSON) emulating IAM. No native ACL support like canned ACLs... see details |
| Amazon S3 | Object storage | No notable divergence |
| API Changelog | Platform | No notable divergence |
| Elastic Network Interfaces | Ports | No notable divergence |
| Accounts | Projects | OpenStack Projects provide resource isolation (VMs, storage) within a single Keystone deployment; AWS Accounts are full billing/security... see details |
| Route Tables | Routers | AWS per subnet/VPC main. OpenStack L3 routers distributed/central. AWS local intra-VPC implicit. OpenStack BGP-LS opt. |
| Amazon S3 (native reference implementation) | S3 Compatibility | AWS S3 is the reference protocol; Quake AI exposes S3 compatibility via OpenStack Swift s3api middleware over Ceph. Several S3 operations... see details |
| Security Pillar | Security | No notable divergence |
| Security Groups | Security Groups | AWS stateful auto-response. OpenStack stateless explicit. OpenStack port/project. AWS default inbound deny/outbound all. |
| Placement Groups | Server Groups | Policies: cluster/partition/spread vs affinity/anti-affinity. AZ-scoped, no instance moves/merges. Specified at launch via... see details |
| Amazon Machine Images (AMIs) | Snapshots | No notable divergence |
| EBS Snapshots | Snapshots | Per-EBS volume, incremental in S3; not full instance image. Via EC2 CreateSnapshot API, not Nova/Cinder. Async pending state, volume usable... see details |
| Subnets | Subnets | AWS subnets single AZ. AWS public/private by routes. OpenStack by network type. AWS IPv6-only; OpenStack dual-stack. |
| Terraform AWS provider | Terraform | Uses aws_instance resource with AMI IDs; OpenStack uses openstack_compute_instance_v2 with image names/IDs. AWS provider uses... see details |
| API Changelog | Tools | AWS publishes API changes through What's New feed and service-specific changelogs; Quake AI uses a unified api-changelog page |
| S3 Versioning | Versioning | Supported via S3 API (enable/suspend, list/delete versions); counts all versions toward quota. Console shows only latest size, no version... see details |
| Amazon EBS volumes | Volumes | Strictly bound to a single Availability Zone where created; cannot be moved without snapshot. Multiple volume types (gp3, io2, st1) with... see details |
Azure to Quake AI
| Azure service | Quake AI equivalent | Key difference |
|---|---|---|
| Management Groups + Subscriptions + Resource Groups hierarchy | Account | Azure's organization model is a four-level hierarchy: Tenant (Entra ID) → Management Groups → Subscriptions → Resource Groups. OpenStack... see details |
| Microsoft Entra ID (formerly Azure AD) | Authentication | Proprietary Microsoft identity platform with OAuth2/OIDC, MSAL libraries, Microsoft Graph API integration; OpenStack Keystone provides... see details |
| Resource Manager deployment (deployment) | Automation | Authoring format differs: ARM templates are JSON documents for Azure Resource Manager deployments, whereas Quake AI offers Heat (legacy,... see details |
| Billing | Billing | Consumption-based metered billing via Microsoft Commerce pipeline with rated usage, monthly invoices, discounts/reservations; OpenStack has... see details |
| Pay-As-You-Go (per-second billing for Linux VMs, regional pricing) | Billing | Azure bills Linux VMs per second; pricing is not included in the VM size API and requires the Azure Retail Prices API (GET... see details |
| Copy Managed Disk | Clones | Azure cloning via 'az disk create --source' from disk ID or snapshot, supports cross-subscription/region with grants; Cinder uses 'cinder... see details |
| Storage Service Encryption (SSE) | Encryption | Both SSE transparent; Azure SSE default with Microsoft-managed keys (256-bit AES), optional CMK in Key Vault/CPK/client-side; Swift... see details |
| VM sizes | Flavors | Predefined hardware-optimized series (e.g., D-family general purpose) with complex naming (e.g., Standard_D4as_v5), not user-defined... see details |
| Public IP addresses | Floating IPs | Public IP is a dedicated ARM resource with SKUs (Basic/Standard); IPv4 billed, IPv6 free (). Static/dynamic allocation (Standard static... see details |
| Compute Gallery image definitions and versions | Images | Organized in galleries with image definitions and versioned images (Microsoft.Compute/galleries/images/versions), more structured than flat... see details |
| Virtual Machines | Instances | Uses Azure Resource Manager (ARM) REST API at /providers/Microsoft.Compute/virtualMachines instead of OpenStack Nova API at /v2.1/servers.... see details |
| SSH public keys | Key Pairs | Managed as ARM resources (Microsoft.Compute/sshPublicKeys), reusable across VMs, vs OpenStack's keypairs injected only at boot. API... see details |
| AKS Cluster | Kubernetes | Azure automatically provisions and manages the control plane at no additional cost (Free tier) or fixed fee (Standard tier with SLA),... see details |
| NAT Gateway | NAT | Managed subnet-level service w/ dynamic SNAT ports (no exhaustion), up to 16 static Public IPs (). Highest precedence over LB/instance... see details |
| Load Balancer | Network | Pure L4 (TCP/UDP) pass-through; no L7 features (use App Gateway) (). SKUs: Standard w/ zones/HA, health probes, outbound SNAT rules; Basic... see details |
| AKS Networking | Networking | Azure CNI or kubenet, integrates Azure Load Balancer/Application Gateway; Quake AI Kubernetes clusters use Neutron private networks and... see details |
| Virtual Network (VNet) | Networks | Azure VNets are strictly regional Layer 3 overlays scoped to one subscription with no L2 VLAN support (). VNets and subnets creation free,... see details |
| Blob Storage | Object storage | No notable divergence |
| RBAC / ABAC / SAS | Object storage | Azure uses RBAC/ABAC with Entra ID (AAD), SAS, shared keys; Quake AI/OpenStack Swift S3 uses Keystone/S3 token auth mapped to Swift ACLs,... see details |
| Network Interfaces | Ports | No notable divergence |
| Subscriptions | Projects | Resource Groups store metadata in a specific region and support resources from multiple regions; OpenStack lacks formal grouping beyond... see details |
| Virtual Network Gateway | Routers | No notable divergence |
| Blob lifecycle management | S3 | Azure supports automated tiering (hot/cool/cold/archive) and expiration rules based on age, access time; Quake AI Swift S3 API lacks native... see details |
| N/A (No native S3 API — Azure Blob Storage REST API only) | S3 Compatibility | Azure Blob Storage has no native S3-compatible endpoint; S3 compatibility requires third-party gateways (Flexify.IO, S3Proxy). Applications... see details |
| Network Security Groups (NSGs) | Security Groups | NSGs can associate to both subnets and NICs with specific processing order (inbound: subnet then NIC; outbound: NIC then subnet) ().... see details |
| Availability sets | Server Groups | Uses fault/update domains (max 3/20) for HA, fixed at creation, vs flexible OpenStack server group policies (affinity/anti-affinity). ARM... see details |
| Compute Gallery Image (Generalized or Specialized) | Snapshots | Azure requires choosing between generalized (sysprep'd, removes machine identity, destroys the source VM's bootability) and specialized... see details |
| Snapshots | Snapshots | Snapshots of managed disks (Microsoft.Compute/snapshots), billed on used size, separate from volumes unlike Cinder volume snapshots... see details |
| Virtual Network Subnets (VNet Subnets) | Subnets | Azure subnets are child resources of a Virtual Network defined as /providers/Microsoft.Network/virtualNetworks/{vnet}/subnets/{subnet};... see details |
| Terraform AzureRM provider | Terraform | Uses azurerm_virtual_machine/azurerm_linux_virtual_machine; OpenStack uses openstack_compute_instance_v2. AzureRM provider requires... see details |
| Blob versioning | Versioning | Both support versioning via S3 API in Quake AI and Blob REST API in Azure, but Azure automatic on write/delete for supported accounts;... see details |
| Managed Disks | Volumes | Azure Managed Disks are fully managed with automatic redundancy (3 replicas, 99.999% SLA); Cinder durability depends on backend. Predefined... see details |
Google Cloud to Quake AI
| Google Cloud service | Quake AI equivalent | Key difference |
|---|---|---|
| Organizations | Account | Organizations auto-provisioned for Google Workspace/Cloud Identity accounts with immutable owner directory ID; OpenStack domains are... see details |
| Cloud Identity / IAM | Authentication | Role-based with predefined/custom roles (permissions as service.resource.verb); Keystone uses simpler flat roles assigned to... see details |
| Deployment Manager | Automation | Uses YAML configurations with optional Jinja2/Python templates expanded server-side; Quake AI offers Heat (legacy, HOT/YAML) and recommends... see details |
| GKE Pricing | Billing | Per-hour cluster platform fee with a free tier allowance; Autopilot offers pod-based billing as an alternative model. On Quake AI, whether... see details |
| Google Compute Engine Pay-As-You-Go (per-second billing, automatic sustained use discounts) | Billing | GCP bills all VM instances per second with no minimum charge per instance. Sustained use discounts apply automatically (up to 30% discount)... see details |
| N/A (No subscription layer — GCP Billing Accounts linked to Projects) | Billing | GCP has no subscription concept. A Billing Account is linked to one or more Projects; usage across linked projects is aggregated and... see details |
| Disk Clones | Clones | Direct disk-to-disk cloning (zonal-to-zonal or zonal-to-regional) without intermediate snapshot, synchronous and instantly usable (regional... see details |
| Compute Engine | Compute | No notable divergence |
| Default server-side encryption | Encryption | GCP always-on AES-256-GCM Google-managed (no config), +CMEK/CSEK; Swift optional proxy middleware (keymaster+encryption), AES-256-CTR on... see details |
| Machine types | Flavors | Organized by families/series (e.g. N2 general-purpose); OpenStack flavors flat list. Custom types +5% premium for N/E series; no such... see details |
| Static External IP | Floating IPs | GCP static IPs are regional or global resources, with unassociated IPs metered per-hour; OpenStack floating IPs are pool-based. See the GCP... see details |
| Machine Images (full VM state capture) | Images | Public images shareable across projects (e.g. debian-cloud); OpenStack typically tenant-private. Image families point to latest version; no... see details |
| VM instances | Instances | Uses REST API 'instances.insert' instead of Nova 'servers.create' with different auth via service accounts vs Keystone. Supports bare metal... see details |
| SSH keys | Key Pairs | Managed in project/instance metadata or OS Login (IAM); no central 'keypairs' resource like Nova. Auto-generates ephemeral keys for... see details |
| GKE Cluster | Kubernetes | GKE provides Autopilot mode with fully managed node provisioning and scaling by Google; on Quake AI you provision clusters through Magnum... see details |
| Cloud NAT | NAT | GCP Cloud NAT is a managed service on top of Cloud Router; OpenStack SNAT is built into the L3 router agent/OVN. GCP NAT supports port... see details |
| Cloud Load Balancing | Network | GCP offers external and internal, global and regional, HTTP, TCP, and UDP load balancers. Quake AI workloads use a self-managed reverse... see details |
| VPC Networking | Networking | Per-cluster Neutron networks + floating IPs; GKE shared VPC with alias IP ranges. Kubernetes LoadBalancer behavior replaces Google Cloud... see details |
| VPC Network | Networks | GCP VPC is global (spans all regions) whereas OpenStack Neutron networks are project-scoped and region-local. GCP uses shared VPC for... see details |
| Storage | Object storage | No notable divergence |
| Network Interface (VM network config) | Ports | GCP VMs have network interfaces attached at creation; OpenStack ports are explicit Neutron resources manageable independently. GCP... see details |
| Projects | Projects | GCP Projects have both human-readable Project ID (custom) and auto-generated numeric Project Number, used interchangeably in APIs unlike... see details |
| Cloud Router | Routers | GCP Cloud Router is a BGP speaker for dynamic route exchange with VPN/Interconnect; OpenStack routers are L3 gateways with static routes.... see details |
| Cloud Storage S3-compatible XML API | S3 Compatibility | GCP Cloud Storage has an S3-compatible XML API at storage.googleapis.com; auth uses HMAC keys generated separately from GCP service account... see details |
| Firewall Rules | Security Groups | GCP firewall rules are VPC-level with target filtering by network tags or service accounts; OpenStack security groups attach to ports. GCP... see details |
| Sole-Tenant Nodes / Instance Groups | Server Groups | MIGs offer autoscaling, autohealing, rolling updates via templates; OpenStack only scheduling policies (affinity etc.). Zonal/regional with... see details |
| Standard/Archive Snapshots | Snapshots | Crash-consistent point-in-time copies stored incrementally in Cloud Storage (geo-redundant by default), unlike Cinder snapshots which... see details |
| Subnets | Subnets | GCP subnets are regional (cover all zones in a region); OpenStack subnets are project-scoped within a network. GCP supports secondary IP... see details |
| Terraform google provider | Terraform | Uses HCL with google_compute_instance, google_storage_bucket etc.; Quake AI uses the OpenStack Terraform/OpenTofu provider with... see details |
| Object Versioning | Versioning | GCP bucket-level enable, auto live/noncurrent via generation/metageneration, DELETE noncurrent permanent (w/gen), costs all versions +... see details |
| Persistent Disk | Volumes | Uses Google Compute Engine REST API instead of OpenStack Cinder API. Offers multiple performance tiers (pd-standard HDD, pd-balanced SSD,... see details |
DigitalOcean to Quake AI
| DigitalOcean service | Quake AI equivalent | Key difference |
|---|---|---|
| Teams | Account | DigitalOcean Teams allow multiple users to share access to one billing account's resources. There is no hierarchy above the team level;... see details |
| Personal Access Tokens | Authentication | DigitalOcean PATs are account-scoped (access all resources across all projects for that account) with a choice of read or read/write scope.... see details |
| Billing API | Billing | REST endpoints for balance, history, invoices (PDF/CSV), insights via team URN (do:team:uuid). Usage-based with monthly invoices on 1st;... see details |
| N/A (No subscription model — usage-based monthly billing) | Billing | DigitalOcean has no subscription model; billing is usage-based with a monthly invoice. Resources are billed from provisioning to deletion... see details |
| Spaces subscription + bandwidth overage pricing | Billing | DigitalOcean charges a flat monthly base fee for a Spaces Standard Storage subscription that includes pooled storage and outbound transfer... see details |
| Space (bucket) | Containers | Naming differs: users create a “Space” that is a bucket, and each bucket has a unique URL (virtual-hosted or path style), whereas Swift... see details |
| Droplet sizes (plans) | Flavors | A Droplet must select a predefined “size” bundle (RAM/vCPU/disk/transfer) rather than choosing from an OpenStack flavor catalog that many... see details |
| Reserved IPs (formerly Floating IPs) | Floating IPs | Naming/API surface: DigitalOcean renamed Floating IPs to Reserved IPs; endpoints and fields change from `floating_ips` to `reserved_ips`... see details |
| Images (Distributions, 1-Click Apps, Snapshots, Backups, Custom Images) | Images | DigitalOcean classifies images into specific types (snapshots, backups, applications/1-Click, distributions, custom) rather than OpenStack... see details |
| Droplets | Instances | API surface is DigitalOcean’s proprietary REST/CLI/Terraform tooling rather than OpenStack Nova/Neutron/Glance APIs (Droplets are managed... see details |
| SSH keys (Account/Team SSH keys) | Key Pairs | SSH keys are managed at the account/team level via /v2/account/keys and then referenced by ID/fingerprint when creating Droplets, whereas... see details |
| Kubernetes Cluster | Kubernetes | Uses proprietary DigitalOcean API (POST /v2/kubernetes/clusters) for provisioning; Quake AI users provision Nova instances via OpenTofu and... see details |
| VPC NAT Gateway (outbound-only, GA November 2025) | NAT | DO VPC NAT Gateway (POST /v2/vpc_nat_gateways) provides outbound internet egress (SNAT) for private Droplets only; it does not support... see details |
| Load Balancers (Regional Load Balancers and Global Load Balancers) | Network | Product shape: DigitalOcean provides regional and global managed load balancers. Quake AI workloads use a self-managed reverse proxy,... see details |
| VPC-native Networking with Cilium | Networking | VPC-native using Cilium eBPF (K8s 1.31+), Gateway API default on 1.33+; Quake AI Kubernetes clusters use CNI plugins (Flannel, Calico,... see details |
| VPC (VPC Network) | Networks | Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas... see details |
| Spaces Object Storage | Object storage | No notable divergence |
| N/A (No port resource — network interfaces are implicit per Droplet) | Ports | DigitalOcean has no port concept. Droplets receive a private VPC IP automatically on creation; the network interface is implicit and not... see details |
| Projects | Projects | UI/organizational grouping of resources (Droplets, Spaces, etc.) into named projects with description/purpose/environment; default project... see details |
| N/A (No router resource — VPC NAT Gateway for egress only; no inter-VPC routing) | Routers | DigitalOcean has no managed router resource. The VPC NAT Gateway (GA November 2025) handles outbound internet egress for private Droplets;... see details |
| Spaces API (S3-compatible RESTful XML API) | S3 Compatibility | Spaces documents that it implements only a subset of the Amazon S3 API; migrating users may need to validate specific S3... see details |
| Security | Security | No notable divergence |
| Cloud Firewalls | Security Groups | Application model: DigitalOcean firewalls are applied to Droplets via `droplet_ids` and/or tags, whereas OpenStack security groups are... see details |
| Cloud Firewalls | Security Groups | Applied to Droplets via droplet_ids and/or tags; Neutron security groups attach to ports. Both inbound and outbound rules; default deny all... see details |
| Tags (for grouping Droplets) | Server Groups | DigitalOcean uses tags as a grouping/selection mechanism (filtering, bulk actions, auto-inclusion in firewall/LB configs) rather than... see details |
| Droplet Snapshots | Snapshots | DigitalOcean requires the Droplet to be powered off for a consistent snapshot (POST /v2/droplets/{id}/actions with {"type": "snapshot"}); a... see details |
| Volume Snapshots | Snapshots | Proprietary API /v2/volumes/{volume_id}/snapshots instead of OpenStack /v3/{project_id}/snapshots. Explicitly crash-consistent only, no... see details |
| N/A (No manual subnet management — VPC handles IP assignment automatically) | Subnets | DigitalOcean VPCs automatically manage an internal IP range; users cannot create, delete, or resize subnets. Neutron subnets are explicitly... see details |
| API | Tools | Uses REST API over HTTPS with Bearer token authentication via personal access tokens, not OpenStack's Keystone token-based auth. Base URL... see details |
| Volumes | Volumes | Uses proprietary /v2/volumes API instead of OpenStack Cinder /v3/{project_id}/volumes; actions like attach/detach/resize via undocumented... see details |
Hetzner to Quake AI
| Hetzner service | Quake AI equivalent | Key difference |
|---|---|---|
| Project Members | Account | Console/email invite-based with fixed roles (Owner/Admin/Member/Restricted); no Keystone users/roles/groups API. Owner uniquely billed for... see details |
| Projects (flat, no organization hierarchy above project level) | Account | Hetzner has no organization or team hierarchy above the project level. Multiple Hetzner accounts cannot be grouped into an organization;... see details |
| API Token | Authentication | Hetzner API tokens are project-scoped: each token is valid only for the project it was created in and must be separately generated per... see details |
| Cloud hourly/monthly pricing with monthly cap | Billing | Hetzner bills servers per hour with a monthly cap; if a server is deleted before month end, only the hourly rate applies. Servers are... see details |
| N/A (No subscription model — pay-as-you-go with monthly invoices per project) | Billing | Hetzner has no subscription or commitment model; all billing is usage-based with monthly invoices. There are no reserved instance discounts... see details |
| Project Billing | Billing | Hourly pro-rated with monthly cap, invoiced monthly post-usage to project Owner vs real-time OpenStack usage data via Ceilometer/gnocchi.... see details |
| Buckets | Containers | S3 API (PUT Bucket requires specific headers like x-amz-acl limited to private/public-read, LocationConstraint); Swift uses POST/PUT... see details |
| Server Types | Flavors | Fixed predefined types (e.g. CX11, CPX31) with shared_vcpu (noisy neighbors) vs dedicated_vcpu. GET /v1/server_types lists all; no custom... see details |
| Floating IPs | Floating IPs | Flat monthly billing €3/IPv4 or hourly equivalent, not usage-based per hour (). Locked to specific location/zone, cannot move across... see details |
| Images | Images | Includes system images (OS), user images (snapshots/backups). API /v1/images; create via server action create_image (type=snapshot/backup).... see details |
| Cloud Servers | Instances | Servers provisioned individually via Hetzner API (hcloud), not OpenStack Nova flavors; fixed instance types like CX11 (1 vCPU, 2GB RAM,... see details |
| SSH Keys | Key Pairs | API /v1/ssh_keys; POST public_key, name; inject array of ssh_keys on server create. No private key management; user provides public keys... see details |
| No managed Kubernetes service (self-managed with CCM and CSI) | Kubernetes | Similar self-managed model to Quake AI; both require users to provision servers and install Kubernetes with tools like OpenTofu/Terraform... see details |
| N/A (No managed NAT service — self-managed Linux NAT server required) | NAT | Hetzner has no managed NAT gateway service. Outbound internet access for private servers requires provisioning a server with a public IP,... see details |
| Cloud Load Balancers | Network | Provisioned via CCM using annotations like load-balancer.hetzner.cloud/location=fsn1 on Services type LoadBalancer. Separate billed... see details |
| Cloud Networking (Private Networks + Floating IPs + Firewalls) | Networking | Hetzner's network model has three main primitives: Private Networks (L3 SDN), Floating IPs (public IP reassignment), and Firewalls... see details |
| Networks | Networks | Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs. CCM supports route... see details |
| Object Storage | Object storage | No notable divergence |
| S3 Credentials (Access Key / Secret Key) | Object storage | Project-scoped keys valid for all buckets in project by default; restrict via policy on key (Hetzner-specific?); Quake AI/Swift uses... see details |
| API Changelog | Platform | No notable divergence |
| N/A (No port resource — server network interfaces managed implicitly via attach action) | Ports | Hetzner has no port concept. Network attachment is managed at the server level via POST /v1/servers/{id}/actions/attach_to_network with an... see details |
| N/A (No router resource — static routes via network routes API) | Routers | Hetzner has no managed router resource. Inter-subnet and internet routing is configured via static routes in the network (POST... see details |
| Object Storage (S3-compatible, Ceph-backed) | S3 Compatibility | Hetzner Object Storage endpoint format is location-scoped: {bucket}.{location}.your-objectstorage.com (e.g.... see details |
| hcloud_firewall | Security Groups | Stateful rules by direction (in/out), protocol, port; apply_to via server IDs or label_selector (project-wide). Attach via firewall_ids in... see details |
| Placement Groups | Server Groups | Only 'spread' type (anti-affinity: servers on different physical hosts); no 'affinity' or policy-based like OpenStack. Max 10 servers/group... see details |
| N/A (No equivalent) | Snapshots | No support for volume snapshots in API or console; explicitly stated 'we do not provide Backups or Snapshots for Volumes' and server... see details |
| Server Snapshots (Image type: snapshot) | Snapshots | Hetzner server snapshots are created via POST /v1/servers/{id}/actions/create_image with type: snapshot. Hetzner recommends powering off... see details |
| Private Network Subnets | Subnets | Hetzner subnets are defined with a network_zone (e.g. eu-central) and an IP range within the parent network CIDR via POST... see details |
| Cloud API | Tools | Proprietary REST API over HTTPS with Bearer token auth, not OpenStack Identity API (keystone) endpoints or mechanisms. Base URL... see details |
| Object Versioning | Versioning | Supported in both, but Hetzner S3 limited NoncurrentVersionExpiration to NoncurrentDays only. |
| Cloud Volumes | Volumes | Provisioned via Hetzner CSI driver (csi.hetzner.cloud), ReadWriteOnce only, min 10GB, NVMe-based. Billed €0.044/GB/month until deleted, no... see details |
Linode to Quake AI
| Linode service | Quake AI equivalent | Key difference |
|---|---|---|
| Object Storage buckets | Containers | Linode exposes buckets through a dedicated Object Storage API rather than as Swift containers. The canonical API summary lists `GET... see details |
| types | Flavors | Linode exposes flavors as account-level "types" returned by the List types API, which the docs say are used when creating or resizing... see details |
| Additional IPv4 addresses | Floating IPs | Linode does not model this as a separate Neutron floating IP pool resource. The canonical guide describes adding, deleting, transferring,... see details |
| Custom Images | Images | Linode treats custom images as account images that you either capture from an existing Linode disk or upload yourself, and the service... see details |
| Linodes (Compute Instances) | Instances | Provisioned via the Linode API v4 (/v4/linode/instances) instead of OpenStack Nova /v2.1/servers; auth is a Personal Access Token rather... see details |
| Profile SSH keys | Key Pairs | Linode manages SSH keys under the Profile resource, with `GET /v4/profile/sshkeys`, `POST /v4/profile/sshkeys`, `GET... see details |
| Kubernetes Engine (LKE) Cluster | Kubernetes | LKE provides a fully managed control plane (free Standard tier or paid Enterprise tier with HA and SLA); on Quake AI you provision the... see details |
| Allow public IPv4 access (1:1 NAT) | NAT | Linode exposes this as a per-VPC-interface option called Allow public IPv4 access (1:1 NAT), not as a standalone managed NAT gateway... see details |
| NodeBalancers | Network | NodeBalancers are a managed L4/L7 load balancer product. Quake AI workloads use a self-managed reverse proxy or Kubernetes LoadBalancer... see details |
| VPC | Networks | VPCs are region-scoped and isolate Linodes from the public internet and from other customers; OpenStack networks are project-scoped Neutron... see details |
| interfaces | Ports | Linode does not expose a standalone Neutron-style port object; the documented network interface model is per-Linode, and interfaces are... see details |
| Object Storage (S3 API) | S3 Compatibility | Linode Object Storage is S3-compatible by design; the S3 API is the primary programmatic surface, not Swift. Access keys are managed in... see details |
| Cloud Firewalls | Security Groups | Akamai/Linode Cloud Firewalls are the supported managed firewall product; there is no separate Neutron FWaaS-style abstraction. Each... see details |
| Placement Groups | Server Groups | OpenStack Nova server groups expose scheduling policies like affinity and anti-affinity at the API level, but Linode Placement Groups only... see details |
| Block Storage volumes | Snapshots | Linode Block Storage is modeled as independent Volumes that you attach and mount to a Linode, rather than an OpenStack Cinder... see details |
| Images / Backups | Snapshots | Linode exposes instance-level snapshots through the Images and Backups APIs rather than as a Nova-style instance_snapshot resource. The... see details |
| Block Storage Volumes | Volumes | Managed via /v4/volumes on the Linode API; OpenStack uses Cinder /v3/{project_id}/volumes. Volumes are region-scoped and cannot move... see details |
Vultr to Quake AI
| Vultr service | Quake AI equivalent | Key difference |
|---|---|---|
| Buckets | Containers | Vultr calls the OpenStack Swift container equivalent a bucket, and the docs describe buckets as the primary organizational unit for storing... see details |
| Plans | Flavors | Vultr treats instance sizes as predefined Plans, defined as a particular configuration of vCPU, RAM, SSD, and bandwidth, rather than... see details |
| Reserved IPs | Floating IPs | Vultr models the resource as an account-scoped Reserved IP rather than an OpenStack-style floating IP pool object. The doc says Reserved... see details |
| Custom ISO | Images | Vultr names the feature "Custom ISO" and describes it as attaching and booting custom ISO images on a VX1 Cloud Compute instance, rather... see details |
| Cloud Compute / Bare Metal Instances | Instances | Provisioned via the Vultr API v2 (/v2/instances and /v2/bare-metals) instead of OpenStack Nova /v2.1/servers; auth is a Personal Access... see details |
| SSH Keys | Key Pairs | Vultr documents SSH Keys as an account-level resource under Account > SSH Keys, with dedicated create and list endpoints at... see details |
| Kubernetes Engine (VKE) Cluster | Kubernetes | VKE provides a free managed control plane with optional HA upgrades; on Quake AI you provision the cluster through Magnum or self-managed... see details |
| NAT Gateway | NAT | Vultr documents NAT as a separate managed feature inside VPC Networks rather than an OpenStack Neutron router construct. The canonical page... see details |
| Load Balancers | Network | Vultr Load Balancers are a managed L4/L7 product configured per region with forwarding rules, health checks, and sticky sessions. Quake AI... see details |
| VPC Networks | Networking | Vultr’s base private networking primitive is a region-scoped VPC network, described as a private, isolated network for Vultr resources,... see details |
| VPC 2.0 | Networks | VPC 2.0 networks are region-scoped Layer-2 segments with customer-defined CIDR; OpenStack Neutron networks are project-scoped with explicit... see details |
| Object Storage | Object storage | No notable divergence |
| VPC Networks | Ports | Vultr describes this model as a "private, isolated network" for communication between Vultr resources, rather than an OpenStack... see details |
| N/A (No equivalent — Vultr VPC Networks do not expose an OpenStack-style router resource; routing is handled with a dedicated network gateway instance and static routes) | Routers | Vultr’s VPC docs do not define a first-class router object like OpenStack Neutron routers. Instead, the FAQ says VPC does not support... see details |
| Object Storage | S3 Compatibility | Vultr documents its object storage as "S3-compatible APIs" and points users to an "S3 Compatibility Matrix," which frames compatibility as... see details |
| Firewall Groups | Security Groups | Vultr Firewall Groups are the supported managed firewall product; there is no separate Neutron FWaaS-style abstraction on Vultr. A single... see details |
| Tags | Server Groups | Vultr documents instance tagging on the compute instance create and update APIs, not an OpenStack-style scheduler resource. The canonical... see details |
| Snapshots | Snapshots | Vultr’s snapshots are documented as instance snapshots that capture the full state of compute instances, rather than a separate OpenStack... see details |
| Snapshots / Auto Backups | Snapshots | Vultr exposes this as two separate features, "Snapshots" and "Auto Backups", rather than one Nova instance-snapshot object model. The... see details |
| VPC 2.0 | Subnets | Vultr exposes subnet settings as fields on the VPC resource rather than as a standalone subnet object. In the deprecated VPC 2.0 API, `POST... see details |
| Block Storage | Volumes | Managed via /v2/blocks on the Vultr API; OpenStack uses Cinder /v3/{project_id}/volumes. Block Storage offers two performance tiers (HDD... see details |
Background#
- How Quake AI uses OpenStack: the service-to-project map between Quake AI products and the upstream OpenStack projects (Nova, Neutron, Cinder, Swift, and friends).
- OpenStack for AWS developers: why an OpenStack-backed platform is simpler in the dimensions that matter for AWS-trained engineers.
- The platform overview documents pricing model differences (fixed monthly, no egress charges, no per-API-call billing).
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.
For the full policy, see Usage Guidelines.
Last validated: 25.06.2026