Skip to content
Migration

Coming from AWS

Evaluation · Updated Jun 2026

Coming from another cloud?

▸AWS·EC2 Instances, Amazon S3, IAM Users, Amazon Virtual Private Cloud, Security Groups, EBS, ELB, Amazon EKS Cluster, Stacks

EC2 Instanceshigh

  • Uses EC2 RunInstances API instead of Nova servers.create.
  • Requires predefined instance type selection.
  • Supports per-second On-Demand billing and Spot/Reserved options.
  • Includes hibernation state not standard in OpenStack.
AWS docs ↗

Amazon Virtual Private Cloudhigh

  • AWS VPC is regional with CIDR /16-/28.
  • OpenStack Networks project-scoped L2 with flexible CIDR.
  • AWS requires IGW for public.
  • OpenStack provider nets or floating IPs.
AWS docs ↗

Security Groupshigh

  • AWS stateful auto-response.
  • OpenStack stateless explicit.
  • OpenStack port/project.
  • AWS default inbound deny/outbound all.
AWS docs ↗

Amazon EKS Clusterhigh

  • EKS control plane fully AWS-managed, single-tenant, across 3 AZs with auto scale/replace; on Quake AI you run the control plane on Nova instances, provisioned through Magnum or self-managed with OpenTofu, and you operate it.
  • EKS regional API endpoint with SLA; Quake AI exposes the kube API via Neutron LB with floating IP.
  • EKS charges a per-hour cluster platform fee on top of the underlying compute; Quake AI charges only for underlying Nova/Neutron/Cinder resources with no K8s platform fee.
  • EKS managed nodes auto AMI updates, Spot integration; Quake AI self-managed nodes require manual OS image selection and update management.
AWS docs ↗

Stackshigh

  • Quake AI offers Heat (legacy OpenStack orchestration) and recommends OpenTofu for new IaC work; EKS uses declarative console/CLI.
  • EKS Auto Mode automates data plane; Quake AI uses OpenTofu modules for infrastructure provisioning.
  • CloudFormation stacks are managed via AWS-specific REST API (e.g., cloudformation.us-east-1.amazonaws.com) requiring AWS SigV4 auth, while Heat (legacy) uses OpenStack Identity API v3 (keystoneauth) and OpenTofu uses the OpenStack provider with application credentials. Migrators notice different endpoint discovery and auth flows.
  • Stacks support StackSets for cross-region/account deployment; Heat has no equivalent. OpenTofu workspaces offer a different multi-environment pattern.
AWS docs ↗

IAM Usershigh

  • AWS IAM Users are tied exclusively to one AWS account with no native multi-account scoping without Organizations; OpenStack users exist in domains and get scoped to multiple projects via role assignments, allowing flexible multi-tenancy within a deployment.
  • AWS emphasizes long-term credentials like access keys/passwords but strongly recommends federation/temporary creds for humans; OpenStack uses short-lived, scoped tokens natively.
  • Naming: AWS ARNs like arn:aws:iam::ACCOUNT:user/NAME; OpenStack uses user@domain scoped to project@domain.
  • API differences: AWS uses CreateUser, ListUsers in IAM API; OpenStack Keystone v3 API integrates user/project/role in assignments (e.g., POST /v3/role_assignments).
AWS docs ↗

Coming from AWS

If you have been using AWS, here is how Quake AI maps to what you already know. Quake AI runs on OpenStack: the services below expose standard OpenStack APIs with upstream documentation. When a CLI command, error message, or Terraform resource uses a project name like Nova or Neutron, refer to How Quake AI uses OpenStack for the full mapping table.

Quick reference#

AWSQuake AIOpenStack projectKey difference
EC2 InstanceInstanceNovaFlavor model vs instance types; fixed monthly pricing, no per-second billing
S3 BucketContainerSwiftS3-compatible API; endpoint change for most tools
IAM Role / PolicyApplication CredentialKeystoneProject-scoped, not account-wide; no policy language
VPCNetworkNeutronSubnet-router-port model; no IGW, NAT gateway, or route table management
Security GroupSecurity GroupNeutronNearly identical concept; applied per-instance; no cross-account references
CloudFormation / CDKHeat Stack / OpenTofuHeatHOT YAML templates; OpenTofu fits new projects
ELB (ALB / NLB / GWLB)Self-managed edge proxy or API gatewayNova + NeutronRun Caddy, SafeLine, or APISIX on a VM with a floating IP
EKSKubernetes ClusterMagnumManaged control plane; worker nodes are Nova instances
EBS VolumeVolumeCinderSame attach/detach model; NVMe at all tiers
AWS AccountProjectKeystoneProject is the billing and resource isolation unit

Compute: EC2 → Nova instances#

What maps directly: You still launch virtual machines from images, attach networks and volumes, and use SSH keys for access. The Compute service (OpenStack Nova) owns the same lifecycle operations you expect from EC2.

What is different: AWS publishes hundreds of instance types with per-second billing, Spot, and Reserved options. Quake AI exposes a curated catalog of flavors (for example, m2a.large for 2 vCPU and 8 GiB RAM on a general-purpose shape) with fixed monthly pricing tied to your resource tier: there is no per-second meter and no Spot market. Capacity planning maps to flavor + quota, not to a long instance-type catalog. See Flavors for sizes and families.

Create a server with the OpenStack CLI (Nova):

bash
openstack server create \
  --flavor m2a.large \
  --image "Ubuntu 24.04" \
  --network PublicEphemeral \
  --key-name MY_KEY \
  my-server

For the full workflow, see Create an instance. For workload migration steps, see Migrate from EC2.

Object storage: S3 → Swift (S3-compatible)#

What maps directly: You store objects in containers (the S3 “bucket” analog), use keys and prefixes, and talk to an S3-compatible API. Object storage is backed by OpenStack Swift.

What is different: AWS S3 adds lifecycle policies, event notifications, and rich bucket policies. Quake AI exposes an S3-compatible endpoint at object.us-east-2.rumble.cloud: boto3, aws-cli, rclone, and s3cmd work when you point them at that endpoint. You do not get S3 lifecycle rules, S3 event notifications, or AWS-style bucket policy documents; behavior is defined by Swift and the S3 gateway layer. S3 Express One Zone (high-performance directory buckets) is a separate AWS product with no Quake AI equivalent.

Python
import boto3

client = boto3.client(
    "s3",
    endpoint_url="https://object.us-east-2.rumble.cloud",
    aws_access_key_id="ACCESS_KEY_ID",
    aws_secret_access_key="SECRET_ACCESS_KEY",
    region_name="REGION",
)

client.list_buckets()

Read Object storage and Migrate from S3 for compatibility detail and cutover steps.

Identity: IAM → Keystone application credentials#

What maps directly: You still authenticate principals, rotate secrets, and scope access to a project. Identity is handled by OpenStack Keystone.

What is different: AWS IAM is a policy language with JSON documents, resource-level grants, roles, users, and groups spanning an organization. Quake AI uses project-scoped application credentials and three roles: admin, member, and reader. No IAM-style policy language exists; authorization is coarser, so you isolate blast radius with separate projects rather than writing fine-grained policy documents.

Generate credentials in the Console: Generate application credentials.

Networking: VPC → Neutron networks#

What maps directly: You still define private address space, attach instances to subnets, and control reachability with routing and security groups. The Network service is backed by OpenStack Neutron.

What is different: A classic AWS VPC layers subnets, an internet gateway, NAT gateways, route tables, and optional NACLs. On Quake AI you create a network, attach a subnet, and connect it to a router. No internet gateway object exists; routers attach to the external network directly. For basic outbound internet access you do not manage NAT gateways or route tables the way you do in a default VPC mental model.

See Networks for the topology Quake AI expects. For network migration steps, see Migrate from AWS VPC.

Security groups: same concept, different API#

What maps directly: Security groups still default to deny inbound and allow outbound, and you express rules as protocol, port, and remote CIDR. The same Neutron security group objects apply whether you attach them during instance creation (Nova) or to ports (Neutron).

What is different: The API surface is OpenStack, not EC2 AuthorizeSecurityGroupIngress. Rule bodies use UUIDs for group references and remote_ip_prefix for CIDRs. The semantics match AWS closely enough that most migration work is re-creating the same port/CIDR matrix under new IDs. One AWS feature has no Neutron equivalent: cross-account security group references (rules that point at another security group by ID across accounts). Neutron security groups are project-scoped, so express that isolation with project boundaries instead.

Compare the CLIs: on AWS you might run aws ec2 authorize-security-group-ingress with group IDs and --ip-permissions. On Quake AI you add rules with Neutron:

bash
openstack security group rule create \
  --protocol tcp \
  --dst-port 443 \
  --remote-ip 0.0.0.0/0 \
  SECURITY_GROUP_NAME_OR_ID

Follow Create a security group.

Automation: CloudFormation → Heat / OpenTofu#

What maps directly: You still declare infrastructure as structured templates and apply them as atomic stacks. OpenStack Heat is the native orchestrator; templates use HOT (Heat Orchestration Template) YAML with types such as OS::Nova::Server.

What is different: AWS CloudFormation and CDK compile down to service-specific resources with deep AWS coupling. On Quake AI, OpenTofu (or Terraform) with the openstack provider is the usual path for new projects: it is broadly compatible with Terraform for the openstack provider, and most existing Terraform configurations port without changes. OpenTofu and Terraform have diverged since the fork, so complex configurations that rely on HashiCorp-specific features may need review; the openstack provider itself works the same on both tools. Heat remains available for stack-native workflows.

HCL
resource "openstack_compute_instance_v2" "web" {
  name            = "web-01"
  flavor_name     = "m2a.large"
  image_name      = "Ubuntu 24.04"
  key_pair        = "MY_KEY"
  security_groups = ["default"]

  network {
    name = "PublicEphemeral"
  }
}

Start with Infrastructure as Code with OpenTofu and, if you are translating templates, Migrate from AWS CloudFormation.

Load balancing: ELB to a self-managed edge#

ELB concepts still apply at the application edge: terminate traffic, define backends, and health-check them. On Quake AI, run an edge reverse proxy, edge WAF, or API gateway on a VM with a floating IP.

Translate ALB listeners and target groups into routes, backend lists, and health checks. Caddy handles automatic HTTPS, SafeLine adds application-layer filtering, and APISIX adds API routing and rate limits. Network Load Balancer and Gateway Load Balancer features require software appliances or an external service selected for the protocol and throughput your workload needs.

Kubernetes: EKS → Magnum#

What maps directly: You get a Kubernetes API, worker nodes, and cluster-scoped objects. Clusters are provisioned through OpenStack Magnum.

What is different: EKS separates the control plane (managed by AWS) from managed node groups or Fargate profiles. Magnum gives you a managed control plane from a cluster template, but worker nodes are Nova instances you size, patch, and scale: there is no Fargate-style serverless worker equivalent. You choose a template (Kubernetes version, COE driver, network integration) and Magnum wires the cluster API to Nova for nodes.

Cluster operations and templates are covered in Kubernetes. For cluster migration steps, see Migrate from EKS.

Block storage: EBS → Cinder volumes#

What maps directly: You create volumes, attach them to one instance at a time, snapshot, and detach. Block storage is backed by OpenStack Cinder.

What is different: AWS segments EBS into gp3, io2, st1, and other types with provisioned IOPS tiers. Quake AI exposes Cinder volumes backed by NVMe at every tier with the same attach/detach workflow: there are no separate IOPS SKUs; performance characteristics are uniform across the offering described in docs.

Create a volume, then attach it to a running instance (Cinder):

bash
openstack volume create --size VOLUME_SIZE_GB MY_VOLUME
openstack server add volume INSTANCE_NAME_OR_ID MY_VOLUME

See Create a volume.

Account model: AWS account to Quake AI project#

What maps directly: You still have users, credentials, and a boundary that owns resources and billing records.

What is different: AWS nests accounts under Organizations with centralized IAM. On Quake AI, the project is the billing and resource isolation unit, typically one project per resource tier. Keystone holds users and roles inside that project instead of spanning a multi-account org tree.

Account structure is summarized in Account.

Self-managed services and deployment patterns#

Quake AI provides infrastructure primitives: compute, networking, storage, Kubernetes, and automation. Application-level managed services are not part of the platform. You compose your own stack from these primitives, using the same open-source tools you already know.

AWS serviceStatus on Quake AIAlternative
Lambda / serverlessNot availableRun containers on a VM or on Kubernetes
RDS / AuroraNot availableSelf-managed PostgreSQL or MySQL on a VM: start from automation templates
DynamoDBNot availableSelf-managed Redis, MongoDB, or PostgreSQL on a VM
SQS / SNSNot availableSelf-managed RabbitMQ, Redis, or NATS
CloudWatchNot availableRun Prometheus, Grafana, or other agents on your instances
Route 53Not availableUse an external DNS provider (Cloudflare, or another registrar)
CognitoNot availableSelf-managed auth (Keycloak, Auth0, or similar)

Platform differences#

  • Outbound transfer: AWS bills for per-GB data egress from most regions (see AWS EC2 on-demand pricing). Quake AI includes outbound transfer in plan pricing, so there is no separate egress line item to model.
  • Fixed monthly pricing: Compute is billed per flavor per month rather than per second. Core networking objects such as networks, routers, floating IPs, and security groups are included in plan pricing instead of metered as separate hourly line items.
  • Flat authorization: Three project-scoped roles (admin, member, reader) replace IAM JSON policy documents. This is less granular than IAM; you compensate with project-level isolation.
  • Baseline networking: Quake AI networks reach the internet through a router attached to an external network. No internet gateway resource, NAT gateway SKU, or custom route table is required for the default path.

Next steps#

Work through these in order if you are onboarding a team, or jump to the topic that matches your migration phase.

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.

For the full policy, see Usage Guidelines.

Last validated: 22.06.2026

Was this page helpful?