Exclusive Access · Invitation Only

Networks and Public Addresses for VMs

A virtual machine's network is Stratum's own networking. Every interface is created, locked to the machine and separated from other tenants before the machine first runs — there is no moment in which a machine is on the network without that protection.

Part of Compute, in early access.

A machine has one to four interfaces, each of one of two kinds:

KindFlagWhat the guest gets
Network interface--network NET or --network NET=IPAn address on one of your managed networks, with that network's prefix
Public interface--public-ip auto or --public-ip IPOne public IPv4 address your provider routes to the server, held on its own (/32)

Network interfaces

Attaching a machine to a network takes one of the network's endpoints — an address and a MAC address that belong together (see Endpoints): the next free one, or the address you name with NET=IP. Then, before the machine starts:

  • the machine gets its own port on the workload bridge;
  • the port is locked to the machine's MAC address, and the address is bound to that MAC: the machine can only ever send as itself, and nothing else can use its address;
  • for a tenant's machine, the port is separated from every other tenant's workloads (below);
  • a bandwidth limit, if you asked for one, is applied.

The guest receives its address, the network's gateway as its default route (if the network has one) and DNS servers through its first boot; nothing needs to be typed inside it. The endpoint stays the machine's until the machine is deleted: detaching it, changing its MAC or deleting its network is refused meanwhile, with a message naming the machine.

A tenant's machine attaches only to that tenant's networks; an operator machine (no tenant) only to networks without a tenant.

Reaching the node and the internet

On its own, a network is a segment: its machines reach each other, and nothing answers on the gateway address. Put the gateway on the node with --host-gateway, and add --snat to let the network's machines reach the internet through the node's public address (see The host gateway):

sudo cenvero-str-ctl tenant create --name acme                      # → t-acme…
sudo cenvero-str-ctl network create --name acme-web --tenant t-acme \
  --cidr 10.30.0.0/24 --gateway 10.30.0.1 --host-gateway --snat     # → net-…
sudo cenvero-str-ctl vm create --name web-01 --tenant t-acme --image img-3f9a1c2e \
  --vcpus 2 --memory 2048 --network net-acme-web --ssh-key-file ~/.ssh/id_ed25519.pub

(Use the ids the commands print.) --dhcp also serves the network's addresses over DHCP — useful for guests that do not read the first-boot configuration. Machines that do read it have a static address and need no DHCP.

Public addresses

A machine can hold one of the extra IPv4 addresses your provider routes to the server — the usual way dedicated-server providers sell them. Add the addresses to the node once, then ask for one when you create the machine:

sudo cenvero-str-ctl routed add 203.0.113.16/29
sudo cenvero-str-ctl vm create --name www --tenant t-acme --image img-3f9a1c2e \
  --vcpus 2 --memory 2048 --public-ip auto --network net-acme-web

The public interface comes first in the guest. The guest holds the address as a single address (/32) with its default route through the node at 169.254.1.1, reached "on-link"; the first-boot configuration sets that up. The address is never translated on its way out, is protected like an endpoint address (only this machine may send from it), counts as the tenant's, and is free again when the machine is deleted.

Public Addresses covers the ranges, what the machine sees in detail, and how traffic reaches it. IPv4 only for now.

Tenants are kept apart

Every tenant network on a node shares one workload bridge, so the separation is applied where each machine joins it — at its port:

  • a tenant's machine receives nothing that another tenant's machine or container sent straight across the bridge — unicast, broadcast or multicast, whatever the protocol;
  • it cannot ask for (ARP) another tenant's addresses or gateway;
  • it may send only from its own addresses — its network address and its public address;
  • traffic routed through the node between two tenants' private networks is refused too.

A tenant's machine does not start if its port cannot be separated; you get an error saying why. Machines of the same tenant talk to each other directly on their network. Machines without a tenant are not separated at their port — put every customer's machines under a tenant. Tenants has the details and the limits.

Bandwidth

--bandwidth-mbps N limits each interface of the machine (in both directions, by its MAC address). For a tenant with a bandwidth cap it is refused: the tenant's cap covers all its machines. Suspending a tenant cuts its machines' traffic; the machines themselves keep running.

Over the API

In POST /api/v1/vms, each entry of networks is either {"network_id": "net-…"} (optionally with "ip") or {"public_ip": "auto"} (or an address), and may carry "bandwidth_mbps":

{ "name": "www", "tenant_id": "t-acme", "image_id": "img-3f9a1c2e", "vcpus": 2, "memory_mib": 2048,
  "networks": [ { "public_ip": "auto" }, { "network_id": "net-acme-web", "ip": "10.30.0.21" } ] }

See also

↓ This page as JSON ↓ All documentation as JSON