{
    "product": "Cenvero Stratum",
    "generated_at": "2026-10-10T15:57:44+00:00",
    "format": "cenvero-docs-v1",
    "document_count": 1,
    "documents": [
        {
            "slug": "compute/networking",
            "title": "Networks and Public Addresses for VMs",
            "category": "Compute",
            "url": "https://www.stratum.cenvero.com/docs/compute/networking",
            "headings": [
                {
                    "level": 1,
                    "text": "Networks and Public Addresses for VMs"
                },
                {
                    "level": 2,
                    "text": "Network interfaces"
                },
                {
                    "level": 3,
                    "text": "Reaching the node and the internet"
                },
                {
                    "level": 2,
                    "text": "Public addresses"
                },
                {
                    "level": 2,
                    "text": "Tenants are kept apart"
                },
                {
                    "level": 2,
                    "text": "Bandwidth"
                },
                {
                    "level": 2,
                    "text": "Over the API"
                },
                {
                    "level": 2,
                    "text": "See also"
                }
            ],
            "word_count": 898,
            "markdown": "# Networks and Public Addresses for VMs\n\nA virtual machine's network is Stratum's own networking. Every interface is\ncreated, locked to the machine and separated from other tenants **before** the\nmachine first runs — there is no moment in which a machine is on the network\nwithout that protection.\n\n> Part of [Compute](/docs/compute/overview), in early access.\n\nA machine has one to four interfaces, each of one of two kinds:\n\n| Kind | Flag | What the guest gets |\n|---|---|---|\n| **Network interface** | `--network NET` or `--network NET=IP` | An address on one of your managed [networks](/docs/networking/overview), with that network's prefix |\n| **Public interface** | `--public-ip auto` or `--public-ip IP` | One public IPv4 address your provider routes to the server, held on its own (`/32`) |\n\n## Network interfaces\n\nAttaching a machine to a network takes one of the network's **endpoints** — an\naddress and a MAC address that belong together (see [Endpoints](/docs/networking/overview#endpoints-how-a-workload-joins-a-network)):\nthe next free one, or the address you name with `NET=IP`. Then, before the\nmachine starts:\n\n- the machine gets its own port on the workload bridge;\n- the port is **locked to the machine's MAC address**, and the address is bound\n  to that MAC: the machine can only ever send as itself, and nothing else can\n  use its address;\n- for a tenant's machine, the port is **separated from every other tenant's**\n  workloads (below);\n- a bandwidth limit, if you asked for one, is applied.\n\nThe guest receives its address, the network's gateway as its default route (if\nthe network has one) and DNS servers through its [first\nboot](/docs/compute/virtual-machines#first-boot); nothing needs to be typed\ninside it. The endpoint stays the machine's until the machine is deleted:\ndetaching it, changing its MAC or deleting its network is refused meanwhile,\nwith a message naming the machine.\n\nA tenant's machine attaches only to that tenant's networks; an operator machine\n(no tenant) only to networks without a tenant.\n\n### Reaching the node and the internet\n\nOn its own, a network is a segment: its machines reach each other, and nothing\nanswers on the gateway address. Put the gateway on the node with\n`--host-gateway`, and add `--snat` to let the network's machines reach the\ninternet through the node's public address (see [The host\ngateway](/docs/networking/overview#the-host-gateway)):\n\n```bash\nsudo cenvero-str-ctl tenant create --name acme                      # → t-acme…\nsudo cenvero-str-ctl network create --name acme-web --tenant t-acme \\\n  --cidr 10.30.0.0/24 --gateway 10.30.0.1 --host-gateway --snat     # → net-…\nsudo cenvero-str-ctl vm create --name web-01 --tenant t-acme --image img-3f9a1c2e \\\n  --vcpus 2 --memory 2048 --network net-acme-web --ssh-key-file ~/.ssh/id_ed25519.pub\n```\n\n(Use the ids the commands print.) `--dhcp` also serves the network's addresses\nover DHCP — useful for guests that do not read the first-boot configuration.\nMachines that do read it have a static address and need no DHCP.\n\n## Public addresses\n\nA machine can hold one of the extra IPv4 addresses your provider routes to the\nserver — the usual way dedicated-server providers sell them. Add the addresses to\nthe node once, then ask for one when you create the machine:\n\n```bash\nsudo cenvero-str-ctl routed add 203.0.113.16/29\nsudo cenvero-str-ctl vm create --name www --tenant t-acme --image img-3f9a1c2e \\\n  --vcpus 2 --memory 2048 --public-ip auto --network net-acme-web\n```\n\nThe public interface comes first in the guest. The guest holds the address as a\nsingle address (`/32`) with its default route through the node at\n**169.254.1.1**, reached \"on-link\"; the first-boot configuration sets that up.\nThe address is never translated on its way out, is protected like an endpoint\naddress (only this machine may send from it), counts as the tenant's, and is\nfree again when the machine is deleted.\n\n[Public Addresses](/docs/networking/public-addresses) covers the ranges, what the\nmachine sees in detail, and how traffic reaches it. IPv4 only for now.\n\n## Tenants are kept apart\n\nEvery tenant network on a node shares one workload bridge, so the separation is\napplied where each machine joins it — at its port:\n\n- a tenant's machine receives nothing that another tenant's machine or\n  container sent straight across the bridge — unicast, broadcast or multicast,\n  whatever the protocol;\n- it cannot ask for (ARP) another tenant's addresses or gateway;\n- it may send only from its own addresses — its network address and its public\n  address;\n- traffic routed through the node between two tenants' private networks is\n  refused too.\n\nA tenant's machine does not start if its port cannot be separated; you get an\nerror saying why. Machines of the **same** tenant talk to each other directly on\ntheir network. Machines without a tenant are not separated at their port — put\nevery customer's machines under a tenant. [Tenants](/docs/tenants) has the\ndetails and the limits.\n\n## Bandwidth\n\n`--bandwidth-mbps N` limits each interface of the machine (in both directions,\nby its MAC address). For a tenant with a bandwidth cap it is refused: the\ntenant's cap covers all its machines. Suspending a tenant cuts its machines'\ntraffic; the machines themselves keep running.\n\n## Over the API\n\nIn `POST /api/v1/vms`, each entry of `networks` is either\n`{\"network_id\": \"net-…\"}` (optionally with `\"ip\"`) or `{\"public_ip\": \"auto\"}`\n(or an address), and may carry `\"bandwidth_mbps\"`:\n\n```json\n{ \"name\": \"www\", \"tenant_id\": \"t-acme\", \"image_id\": \"img-3f9a1c2e\", \"vcpus\": 2, \"memory_mib\": 2048,\n  \"networks\": [ { \"public_ip\": \"auto\" }, { \"network_id\": \"net-acme-web\", \"ip\": \"10.30.0.21\" } ] }\n```\n\n## See also\n\n- [Networking Overview](/docs/networking/overview) — networks, endpoints and the host gateway.\n- [Public Addresses](/docs/networking/public-addresses)\n- [Gateway NAT](/docs/networking/gateway-nat)\n- [Tenants & Bandwidth](/docs/tenants)\n"
        }
    ]
}