VPC
A VPC (Virtual Private Cloud) is an isolated Layer 3 network for resources in one workspace. Resources in the same VPC communicate over private IPs without traversing the public internet. A VPC belongs to one location, and only VMs in that location can attach to it.
Create a VPC
Enter the VPC details
Enter a Name (e.g. production-vpc), choose a Location, and optionally
add a Description.
Choose connectivity
The VPC network and its default subnet are included at no extra charge. A managed NAT gateway is billed while it exists; the summary panel shows its price for the selected location before you create the VPC. Firewall rules still control access to each VM.
Choose the private IP range
- Automatic (default) picks a conflict-free RFC1918 range.
- Custom CIDR — enter a Network address (e.g.
10.10.0.0) and pick a Network size from/22to/28(default/24). The range must be RFC1918 space (10.0.0.0/8,172.16.0.0/12, or192.168.0.0/16) and aligned to the chosen size. If the address is not aligned, the form suggests the nearest valid network address.
VPC ranges in the same account cannot overlap.
Connectivity modes
If an API request omits connectivity_type, the VPC is created as public:
attached VMs keep their own public interface and also receive a private VPC
interface. The portal does not offer this mode.
NAT gateway controls (the gateway card and Add Port Forwarding) appear only on VPCs created with Managed NAT Gateway.
VPC detail page
Click a VPC in the list to open it. The page has four tabs — Overview, Subnets, Attached Nodes, and Reserved VIPs — and an Actions menu with Attach Node, Add Subnet, Add Port Forwarding (NAT VPCs only), Refresh, and Delete VPC.
Overview shows the VPC details (name, location, private CIDR, connectivity, creation time, VPC ID, and description). On a NAT VPC it also shows the NAT gateway and its port forwarding rules.
Subnets
Add a subnet
- Click Actions → Add Subnet (or Add Subnet on the Subnets tab).
- Enter a Name and a CIDR. The CIDR must be a sub-range of the VPC range that does not overlap another subnet.
- Click Create Subnet.
Delete a subnet
On the Subnets tab, click the delete icon on the subnet row. Detach any nodes that use the subnet first.
Private IP ledger
The Subnets tab also lists every reserved and allocated address in the VPC with its subnet, record type, owner, and status. Network and broadcast addresses are reserved implicitly by each subnet.
Attach a VM
Choose the node and subnet
Select a Node — only VMs in the VPC’s location that are not already attached are listed — and a Subnet.
Choose the private IP
Under Private IP assignment, choose:
- Automatic — the next free address in the subnet is claimed for the VM.
- Specific address — enter an unused host address inside the subnet. The network, broadcast, and gateway addresses are rejected.
Choose traffic routing (NAT VPCs)
On a NAT VPC, if the VM already has a network connection, choose:
- Use VPC for internet — internet and private traffic go through the VPC and its NAT gateway. The VM’s current public IP stays connected until you remove it from the VM’s networking settings.
- Private traffic only — the VM keeps its current internet connection and uses the VPC only for private traffic.
A VM with no other network connection uses the VPC as its primary network. If the VM already has a network connection and the VPC is Private only, the VPC carries private traffic only.
The Attached Nodes tab lists each VM with its status, VPC address, subnet, and access type (Private, NAT, or Public IP).
Detach a VM
On the Attached Nodes tab, click the detach icon on the VM’s row, then confirm Detach VM in the Detach VPC Interface dialog. You can attach the VM again later.
A VPC interface that is the VM’s only network path cannot be detached. Give the VM another network path first (for example, attach it to another VPC and use that VPC for internet), then detach this one.
NAT gateway
A Managed NAT Gateway VPC starts with one NAT gateway. The Overview tab shows the gateway’s status and public IP, and whether that IP is a platform-assigned NAT IP or one of your Reserved IPs.
Use a Reserved IP
To give the gateway a stable address you control, click Use Reserved IP (or Replace Reserved IP) on the gateway card, select an unattached Reserved IP in the same workspace and location, and click Attach Reserved IP. Existing port forwarding rules move to the new address. A previous Reserved IP returns to your Reserved IP pool; a platform-assigned address is released.
Delete the NAT gateway
Click Delete NAT Gateway on the gateway card. The dialog shows the impact:
- VMs routed through the gateway lose outbound internet access. Private VPC connectivity remains.
- All port forwarding rules on the gateway are permanently deleted.
- NAT gateway billing stops after deletion.
Choose what happens to the gateway’s public IP:
If VMs or rules are affected, tick the confirmation checkbox, then confirm.
Create a NAT gateway again
After a NAT gateway is deleted, the Overview tab shows Create NAT Gateway (when VMs are attached, the Attached Nodes tab also offers Add Managed NAT). Choose a Public IP — Automatic NAT IP (assigned and released with the gateway) or one of your unattached Reserved IPs — and click Create NAT Gateway. Attached VMs use the new gateway without changing their VPC interfaces or private IPs. Deleted port forwarding rules are not restored.
NAT port forwarding
Port forwarding routes a public port on the NAT gateway to a private service.
Each rule row has Edit, Enable/Disable, and Delete actions. When editing, click Save Changes to apply.
Use the API
First call GET /networking/sites?workspace_id=607005 and copy the exact
site_id from an entry where available is true. A site ID is an opaque
identifier, not a region name.
Delete a VPC
Before you delete a VPC:
- Detach every VM on the Attached Nodes tab.
- Delete the NAT gateway, if the VPC has one.
- Delete every Virtual IP reservation on the Reserved VIPs tab.
Subnets are removed automatically with the VPC. Then click Actions → Delete
VPC and confirm. You can also delete a VPC from the VPC list; its dialog
checks dependencies and offers to delete the NAT gateway first. The API returns
409 Conflict while dependencies remain.
