How Quake AI uses OpenStack
How Quake AI uses OpenStack
Quake AI runs on OpenStack Antelope (2023.1). Each public Quake AI service (compute, networking, storage, automation, and Kubernetes) maps to an OpenStack project. The standard OpenStack CLI, APIs, and Terraform provider work with these public services. If you have existing OpenStack experience, it transfers directly.
You do not need to understand OpenStack to use Quake AI. The documentation uses Quake AI terms, and you can provision and manage infrastructure entirely through the Console, CLI, or Terraform without learning the underlying project names first. The project names appear in CLI commands, API endpoints, Terraform resources, and parts of the Console UI. This page explains the relationship so those names make sense when you encounter them.
What Quake AI deploys#
Each Quake AI service maps to one or more OpenStack projects. The table below shows the primary mapping, what each project handles, and the API endpoint pattern.
| Quake AI service | OpenStack project | What it does | API endpoint |
|---|---|---|---|
| the Console | Skyline | The web UI for Quake AI services. Customized from upstream Skyline. | n/a (browser-only) |
| Compute | Nova | Virtual machine lifecycle: create, start, stop, resize, snapshot, delete | compute.{region}.rumble.cloud |
| Network | Neutron | Private networks, subnets, routers, security groups, floating IPs | network.{region}.rumble.cloud |
| Block Storage | Cinder | Persistent NVMe volumes: create, attach, snapshot, clone, transfer | volume.{region}.rumble.cloud |
| Object Storage | Swift | S3-compatible object storage for files, backups, and media | object.{region}.rumble.cloud |
| Images | Glance | OS images and instance snapshots: the boot source catalog | image.{region}.rumble.cloud |
| Kubernetes | Magnum | Kubernetes cluster provisioning and lifecycle management | container-infra.{region}.rumble.cloud |
| Automation | Heat | Stack-based orchestration using YAML templates | orchestration.{region}.rumble.cloud |
| Identity | Keystone | Authentication, projects, roles, and application credentials | keystone.rumble.cloud |
The Compute API runs version 2.1 (microversion ceiling 2.93). The Identity API runs version 3. For the full endpoint list with clouds.yaml configuration, see Service Endpoints.
Audience#
New to cloud#
You can skip the rest of this page. Follow the Quickstart and use whichever interface you prefer: the Console, the CLI, or OpenTofu (each is available as a tab on step 3).
When you see names like "Nova" or "Neutron" in a CLI command or error message, they refer to the OpenStack projects listed in the table above. The mapping is stable: Compute always means Nova, and Network always means Neutron, so you can treat the names as interchangeable labels for the same service.
Experienced with OpenStack#
Everything works as expected. The CLI is python-openstackclient, installed with pip. Authentication uses openrc.sh with application credentials (generate credentials). Heat templates use standard HOT syntax with resource types like OS::Nova::Server and OS::Neutron::Net. The Terraform provider is openstack, with resources like openstack_compute_instance_v2 and openstack_networking_secgroup_v2.
Quake AI-specific details to note:
- Console UI: the Console is built on upstream OpenStack Skyline with Quake AI-specific layout, navigation, and form customizations. Customer documentation refers to it as the Console or "Cloud Console", not "Skyline". The Console hostname is
sky.{region}.rumble.cloud; the embedded VNC viewer is served fromsky-console.{region}.rumble.cloud. - API rate limits: OpenStack removed built-in rate limiting in Rocky (2018). The Nova and Cinder
/limitsendpoints return"rate": []on Antelope. Any rate limiting in front of the APIs sits at the openresty gateway and does not returnRateLimit-*orRetry-Afterheaders. If you receive HTTP 429, implement exponential backoff. HTTP 413 on this platform indicates quota exhaustion. - Resource tiers: Quake AI uses a tier-based quota model. Your resource tier sets your project's vCPU, RAM, and storage limits. Individual instance launches do not raise the cap.
- Default image: Ubuntu 24.04 with cloud-init pre-configured. See Images for the full public catalog.
- Default key algorithm: ED25519. Quake AI also accepts RSA.
- Networking: Projects include
PublicEphemeral(direct-attach for testing) andPublicStatic(routed via private networks for production). See Networks for the topology model. - Object storage: S3-compatible via the Swift S3 gateway. Standard S3 SDKs work with
--endpoint-url. Native Swift ACLs apply. See the S3 feature compatibility matrix for supported and unsupported S3 features.
Migrating from another cloud#
If you are coming from AWS, GCP, Azure, Hetzner, or another provider, the core concepts map to OpenStack projects with different names:
| Your current platform | Quake AI equivalent | OpenStack project |
|---|---|---|
| AWS EC2 instances / GCP Compute Engine VMs | Instances (flavors define size) | Nova |
| AWS VPC / GCP VPC / Azure VNet | Networks and subnets | Neutron |
| AWS EBS / GCP Persistent Disk / Azure Managed Disk | Volumes | Cinder |
| AWS S3 / GCP Cloud Storage / Azure Blob Storage | Object storage (containers/buckets) | Swift |
| AWS ELB / GCP Cloud Load Balancing | Self-managed reverse proxy, external edge, or Kubernetes Service type: LoadBalancer | Application software, external service, or Kubernetes |
| AWS EKS / GCP GKE / Azure AKS | Kubernetes clusters | Magnum |
| AWS CloudFormation | Heat stacks (or use OpenTofu) | Heat |
| AWS IAM | Application credentials and project roles | Keystone |
Platform differences:
- Databases: deploy PostgreSQL, MySQL, or Redis on instances using automation templates.
- Authorization: Keystone provides
admin,member, andreaderroles at the project level. IAM-style resource policies are absent; use project isolation for separate trust boundaries. - Billing model: your resource tier sets the quota ceiling; individual instance launches do not incur separate charges.
- Terraform provider change: replace
hashicorp/aws(or equivalent) withterraform-provider-openstack/openstack. Resource names change (aws_instancebecomesopenstack_compute_instance_v2). See Introduction to Terraform on Quake AI.
Migration guides for object storage are available at Object storage migration.
Where OpenStack terms appear#
You will encounter OpenStack project names in CLI output, API references, Terraform resources, and troubleshooting docs. This is by design: the tooling runs on OpenStack, and masking the names would make troubleshooting and external documentation harder to use.
- CLI commands: OpenStack CLI commands use the
openstackprefix:openstack server create,openstack network list,openstack volume show - API endpoints: the base URLs use OpenStack service names:
compute.{region}.rumble.cloud(Nova),network.{region}.rumble.cloud(Neutron) - Terraform resources: all resource types use the
openstack_prefix:openstack_compute_instance_v2,openstack_networking_secgroup_v2,openstack_blockstorage_volume_v3 - Heat templates: resource types use the
OS::namespace:OS::Nova::Server,OS::Neutron::Net,OS::Cinder::Volume - Console UI: the Automation section displays Heat Stacks as a menu item; the API dashboard lists OpenStack service names alongside Quake AI service names
- Error messages: API errors reference the originating service: a network conflict returns a Neutron 409, a quota exceeded error references Nova or Cinder
When you search for help with an error, using both the Quake AI service name and the OpenStack project name improves your results. For example, searching "Neutron security group rule conflict" finds upstream OpenStack documentation that applies directly to Quake AI.
OpenStack services Quake AI does not offer#
Quake AI does not offer the following OpenStack projects as public services:
| OpenStack project | What it would provide | Alternative |
|---|---|---|
| Designate | DNS as a service | Use an external DNS provider (Cloudflare, Route 53) or configure DNS on your own instances |
| Octavia | Load balancing as a service | Run HAProxy, Nginx, Caddy, Traefik, or Envoy on Compute, use an external CDN or WAF, or expose Kubernetes workloads with Service type: LoadBalancer |
| Barbican | Key and certificate management | Store application secrets in CI, Kubernetes, or a self-managed secrets service; install TLS certificates on application or reverse proxy instances |
| Cinder Backup | Native volume backup service | Use volume snapshots for point-in-time recovery or volume clones for independent copies |
| Manila | Shared file systems (NFS/CIFS) | Use NFS on a dedicated instance or object storage |
| Ironic | Bare metal provisioning | Not available: all workloads run on virtual machines |
| Trove | Database as a service | Deploy databases on instances using self-managed templates |
| Sahara | Big data processing | Deploy Spark, Hadoop, or other frameworks on instances or Kubernetes clusters |
| Zaqar | Messaging | Use RabbitMQ, Redis, or NATS on instances |
If your workload depends on one of these services, you can self-host the equivalent on Quake AI instances. The automation templates provide validated starting points for common self-managed deployments.
See also#
- Service Endpoints: published service base URLs,
clouds.yamlexample, endpoint discovery - OpenStack CLI: install and configure the
openstackcommand-line client - Install OpenStack client: detailed installation for all platforms
- Application credentials: authenticate CLI and API access
- Quickstart: first steps with Quake AI
- Introduction to Terraform on Quake AI: IaC with the OpenStack provider
- OpenStack upstream documentation: official project docs for all OpenStack services
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.
For the full policy, see Usage Guidelines.
Last validated: 22.06.2026