Coming from GCP
Coming from another cloud?
▸Google Cloud·VM instances, Storage, VPC, Firewall Rules, Cloud Load Balancing, GKE Cluster, Persistent Disk, Cloud Identity / IAM
VM instances
- Uses REST API 'instances.insert' instead of Nova 'servers.create' with different auth via service accounts vs Keystone.
- Supports bare metal instances (no hypervisor), not in standard OpenStack Nova.
- Network interfaces tied to VPC subnets; differs from Neutron ports/floating IPs.
Persistent Disk
- Uses Google Compute Engine REST API instead of OpenStack Cinder API.
- Offers multiple performance tiers (pd-standard HDD, pd-balanced SSD, pd-ssd, pd-extreme) with performance scaling linearly with provisioned size, unlike Cinder's backend-dependent performance.
- Supports regional disks replicated synchronously across 2 zones for higher availability (better than 99.9999% durability), while Cinder volumes are typically zonal unless using replication features.
- Online resize to increase size without detaching; no manual striping/RAID needed as GCP handles distribution automatically.
Firewall Rules
- GCP firewall rules are VPC-level with target filtering by network tags or service accounts; OpenStack security groups attach to ports.
- GCP rules are stateful (implied return traffic); OpenStack security groups also stateful but per Neutron port.
- GCP firewall supports priority (0-65535) with explicit deny rules; OpenStack security groups are allow-only (implicit deny).
- GCP hierarchical firewall policies apply org/folder-wide; OpenStack has no equivalent scope.
Cloud Load Balancing
- GCP offers external and internal, global and regional, HTTP, TCP, and UDP load balancers. Quake AI workloads use a self-managed reverse proxy or Kubernetes LoadBalancer Service.
- GCP global HTTP(S) load balancing uses one anycast IP across regions. Self-managed Quake AI edges use the public IP and topology you provision.
- GCP integrates Cloud CDN, Cloud Armor (WAF/DDoS) with LBs; OpenStack has no native CDN/WAF integration.
- GCP backend services use health checks and instance groups or NEGs. Self-managed Quake AI edges use proxy upstreams or Kubernetes service selectors.
GKE Cluster
- GKE provides Autopilot mode with fully managed node provisioning and scaling by Google; on Quake AI you provision clusters through Magnum or self-managed Kubernetes on Nova instances and manage node scaling yourself.
- Control plane is fully managed with automatic upgrades through release channels; Quake AI requires user-provisioned and user-managed control plane nodes.
- Cluster creation uses gcloud CLI vs OpenStack CLI (openstack coe cluster create).
- Custom machine types, spot VMs, accelerators in node pools; Quake AI K8s nodes use standard Nova flavors.
Cloud Identity / IAM
- Role-based with predefined/custom roles (permissions as service.resource.verb); Keystone uses simpler flat roles assigned to user-project/domain pairs without granular permissions.
- Hierarchical inheritance across Org > Folder > Project; OpenStack Keystone assignments scoped per project/domain without automatic inheritance.
- Supports IAM Conditions for attribute/time-based access, deny policies, VPC Service Controls; no direct OpenStack equivalent.
- Principals include Google groups/service accounts/federated; Keystone uses local users/groups with federation add-ons.
Coming from GCP
If you have been using Google Cloud Platform, here is how Quake AI maps to what you run today. Quake AI maps compute, storage, networking, and identity to OpenStack-backed services with fixed monthly pricing on infrastructure. Quake AI runs on OpenStack: the services below expose standard OpenStack APIs with upstream documentation. Managed application services are where the platforms diverge most.
Quick reference#
| GCP | Quake AI | OpenStack project | Key difference |
|---|---|---|---|
| Compute Engine VM | Instance | Nova | Machine types vs flavors; per-second billing with sustained-use discounts vs fixed monthly |
| Cloud Storage bucket | Container | Swift | GCS exposes an S3-compatible XML API via HMAC keys (extra setup required); Quake AI Swift exposes an S3 endpoint directly. Lifecycle rules and storage classes do not transfer |
| VPC network | Network | Neutron | Subnet-router model; no GCP-style auto/custom subnet modes |
| Firewall Rules | Security Group | Neutron | GCP uses network-level rules with priority ordering; Neutron uses per-instance security groups |
| Cloud Load Balancing | Self-managed edge proxy or API gateway | Nova + Neutron | Run Caddy, SafeLine, or APISIX on a VM with a floating IP; use an external CDN for global edge delivery |
| GKE | Kubernetes Cluster | Magnum | Managed control plane both. GKE Standard has self-managed node pools; GKE Autopilot (serverless, no node management) has no Quake AI equivalent. Magnum workers are self-managed Nova instances |
| Persistent Disk | Volume | Cinder | Same attach model; both NVMe-backed |
| Cloud IAM | Application Credential | Keystone | GCP IAM is org/folder/project hierarchy with fine-grained roles; Quake AI is project-scoped with 3 roles |
| Static external IP | Floating IP | Neutron | Same concept; allocate from pool, associate with instance |
| GCP Project | Project | Keystone | Same isolation unit |
Compute: compute engine virtual machines → instances#
What maps directly: You still launch VMs from images, choose a machine size, attach disks and networks, and use SSH keys. Instances are backed by OpenStack Nova.
What is different: GCP publishes hundreds of machine types (e2, n2, c2, and custom shapes) with per-second billing, sustained-use discounts, and committed-use contracts. Quake AI exposes a curated catalog of flavors across four families (for example, m2a.large for 2 vCPU and 8 GiB RAM on a general-purpose shape) with fixed monthly pricing per resource tier. No sustained-use discount or custom machine type builder exists. Capacity planning maps to flavor + quota. See Flavors for sizes and families.
openstack server create \
--flavor m2a.large \
--image "Ubuntu 24.04" \
--network PublicEphemeral \
--key-name "MY_SSH_KEY_NAME" \
"MY_INSTANCE_NAME"For the full workflow, see Create an instance. For workload migration steps, see Migrate from Compute Engine.
Object storage: Google Cloud Storage → containers (Swift, S3-compatible)#
What maps directly: You store objects in containers (the GCS "bucket" analog), use keys and prefixes, and talk to an S3-compatible API. Object storage is backed by OpenStack Swift.
What is different: GCS adds storage classes (Standard, Nearline, Coldline, Archive), lifecycle rules, event notifications via Pub/Sub, and fine-grained IAM at the bucket and object level. Quake AI exposes a single storage tier with an S3-compatible endpoint. You do not get lifecycle rules, storage class transitions, or event notifications.
Tooling: rclone and boto3 work when pointed at object.us-east-2.rumble.cloud with Quake AI credentials. On the GCP side, gcloud storage replaces the older gsutil CLI. Reaching GCS over the S3 API requires enabling XML API interoperability and creating HMAC keys, so standard boto3 or aws-cli tools need HMAC key configuration on the GCS side, not only a flag.
See Object storage and Migrate from Google Cloud Storage for compatibility detail and cutover steps.
Networking: Google Cloud VPC networks → Neutron networks#
What maps directly: You define private address space, attach instances to subnets, and control reachability with routing and firewall rules. The Network service is OpenStack Neutron.
What is different: GCP VPCs support automatic and custom subnet modes, with subnets spanning regions and firewall rules applied at the network level with priority ordering. On Quake AI, you create a network, attach a subnet, and connect it to a router. No automatic subnet mode, cross-region subnets, or priority-based rule ordering exists. Routers attach directly to the external network for outbound access.
See Networks for the topology Quake AI expects. For network migration steps, see Migrate from GCP VPC.
Security: Google Cloud firewall rules → Neutron security groups#
What maps directly: You still express allow/deny rules by protocol, port, and source CIDR. Both platforms default to deny-inbound.
What is different: GCP firewall rules are network-level resources with explicit priority ordering (lower number = higher priority). Neutron security groups bind to each instance port, have no priority ordering, and use an additive model: all rules that match are applied. When migrating, re-create your allow rules as security group rules. If you relied on GCP deny rules with priority ordering, rethink the logic for an additive-only model.
Follow Create a security group.
Block storage: persistent disks → Cinder volumes#
What maps directly: You create a volume, attach it to one instance, format, mount, snapshot, and detach. Block storage is OpenStack Cinder.
What is different: GCP segments Persistent Disks into pd-standard, pd-balanced, pd-ssd, and pd-extreme with provisioned IOPS tiers. Quake AI exposes Cinder volumes backed by NVMe with the same attach/detach workflow. No separate IOPS tiers exist.
See Create a volume.
Kubernetes: from GKE to Magnum#
What maps directly: You get a Kubernetes API, worker nodes, and cluster-scoped objects. Clusters are provisioned through OpenStack Magnum.
What is different: GKE manages node pools, offers cluster auto-scaler, node auto-provisioning, and Autopilot mode. Magnum gives you a managed control plane from a cluster template, but worker nodes are Nova instances you size, patch, and scale. No Autopilot equivalent is available.
Cluster operations and templates are covered in Kubernetes. For cluster migration steps, see Migrate from GKE.
Automation: from gcloud and Infrastructure Manager to OpenTofu#
What maps directly: You still declare infrastructure as code and apply it as atomic deployments.
What is different: GCP uses gcloud CLI for imperative operations and Infrastructure Manager (Infra Manager) or Terraform with the google provider for declarative infrastructure. (Google Cloud Deployment Manager was deprecated and shut down on 31.03.2026; Infra Manager is its Terraform-backed successor.) On Quake AI, OpenTofu (or Terraform) with the openstack provider is the usual path for new projects. Heat stacks are also available for OpenStack-native templates.
Get started with Infrastructure as Code with OpenTofu.
Identity: Cloud IAM → Keystone application credentials#
What maps directly: You still authenticate principals, rotate secrets, and scope access to a project. Identity is handled by OpenStack Keystone.
What is different: GCP IAM spans an org, folder, and project hierarchy with fine-grained, resource-level roles. Quake AI uses project-scoped application credentials and three roles: admin, member, and reader. No org or folder tier exists, and authorization is coarser, so you isolate blast radius with separate projects instead of layered IAM bindings.
Generate credentials in the Console: Generate application credentials.
Self-managed services and deployment patterns#
Quake AI provides infrastructure primitives: compute, networking, storage, Kubernetes, and automation. Application-level managed services are not part of the platform. You compose your own stack from these primitives, using the same open-source tools you already know.
| GCP service | Status on Quake AI | Alternative |
|---|---|---|
| Cloud Functions / Cloud Run | Not available | Containers on VMs or Kubernetes |
| Cloud SQL | Not available | Self-managed PostgreSQL or MySQL on a VM |
| Cloud Spanner / Firestore / Bigtable | Not available | Self-managed databases on VMs |
| Pub/Sub | Not available | Self-managed RabbitMQ, Redis, or NATS |
| BigQuery | Not available | Self-managed ClickHouse, PostgreSQL, or similar |
| Memorystore | Not available | Self-managed Redis on a VM |
| Cloud DNS | Not available | External DNS provider (Cloudflare or similar) |
| Cloud CDN | Not available | Cloudflare or self-managed caching |
Platform differences#
- Outbound transfer: GCP bills for per-GB data egress with rates that vary by region and destination (see the GCP network pricing page). Quake AI includes outbound transfer in plan pricing, so there is no separate egress line item to model.
- Fixed monthly pricing: Compute is billed per flavor per month rather than per-second metering, sustained-use discounts, or committed-use contracts. Core networking objects such as networks, routers, floating IPs, and security groups are included in plan pricing instead of metered as separate hourly line items.
- Flat authorization: Three project-scoped roles (admin, member, reader) replace GCP's layered org, folder, and project IAM hierarchy. This is less granular than Cloud IAM; you compensate with project-level isolation.
- OpenStack portability: Public APIs use standard OpenStack projects including Nova, Neutron, Cinder, Swift, Magnum, and Keystone. The same toolchains transfer to other OpenStack clouds.
Next steps#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.
For the full policy, see Usage Guidelines.
Last validated: 22.06.2026