Virtual Private Cloud (VPC) Networking
Okustera Virtual Private Cloud (VPC) Networking delivers isolated software-defined networks powered by OpenStack Neutron and the Open Virtual Network (OVN) distributed SDN control plane.
Every tenant project is provisioned within an isolated virtual topology, enabling engineering teams to build multi-tier VPC networks, define stateful distributed firewall rules, route traffic to external gateways, and bind public Elastic Floating IPs.
Key Capabilities
- Isolated Private Overlay Networks: Isolated L2/L3 overlay networks with custom CIDR blocks (e.g.,
192.0.2.0/24,198.51.100.0/24), automated DHCP address assignment, and custom DNS resolvers. - Distributed Virtual Routing: High-throughput distributed East-West and North-South routing connecting private subnets to external gateways with automated Source NAT (SNAT).
- Stateful Security Groups: Kernel-enforced, stateful distributed firewall policies applied directly at the virtual network interface (vNIC) layer.
- Elastic Floating IPs: Public static IPv4 addresses dynamically attached and detached across virtual machines, container ingress gateways, or load balancers.
- Allowed Address Pairs: Support for secondary IP addresses and virtual IP failover protocols (VRRP, Keepalived, Pacemaker) without port security packet drops.
- Octavia Load Balancing Integration: Native integration with Octavia Load Balancers for L4/L7 traffic distribution.
VPC Architecture for Tenants
Managing Networking in the Cloud Portal
The Okustera Cloud Portal (/network) provides visual tools to manage your entire network topology:
1. Creating a Private Network & Subnet
- Navigate to Networking $\to$ Networks in the left sidebar.
- Click Create Network:
- Network Name:
prod-vpc-network - Subnet Name:
prod-app-subnet - Network CIDR: e.g.,
192.0.2.0/24 - Gateway IP: e.g.,
192.0.2.1(or leave default for first IP) - Enable DHCP: Checked (enables automatic IP assignment to instances)
- DNS Nameservers: e.g.,
1.1.1.1,8.8.8.8
- Network Name:
- Click Create.
2. Connecting Subnets to the Virtual Router (Internet Access)
To enable instances in your private subnet to communicate with the outside world:
- Navigate to Networking $\to$ Routers.
- Select your Virtual Router (or click Create Router with External Gateway enabled).
- Click Add Interface and select your newly created subnet (
prod-app-subnet). - All instances in the subnet immediately gain outbound internet access via automated SNAT.
3. Stateful Security Groups (Firewall Rules)
Security groups act as a virtual firewall for your compute instances:
- Navigate to Networking $\to$ Security Groups.
- Click Create Security Group (e.g.
web-tier-sg). - Click Manage Rules to add ingress/egress rules:
- Rule Type: Custom TCP, HTTP (80), HTTPS (443), SSH (22), or Custom ICMP (Ping).
- Direction: Ingress (incoming) or Egress (outgoing).
- Remote Source:
- CIDR Block: e.g.,
0.0.0.0/0(public access) or198.51.100.0/24(corporate office IP). - Security Group Reference: Only allow traffic from instances belonging to another security group (e.g., allow database port
5432only from instances withweb-tier-sg).
- CIDR Block: e.g.,
4. Allocating & Binding Floating IPs
- Navigate to Networking $\to$ Floating IPs.
- Click Allocate IP: Select the
public_externalpool to receive a public static IPv4 address. - Locate your allocated IP and click Associate.
- Select the target compute instance port to bind the public IP. Ingress traffic to this public IP will be forwarded directly to your instance's private IP.
Declarative Configuration via Terraform
# 1. Create Private Network
resource "okustera_network" "vpc" {
name = "production-vpc"
cidr = "192.0.2.0/24"
gateway_ip = "192.0.2.1"
enable_dhcp = true
dns_nameservers = ["1.1.1.1", "8.8.8.8"]
}
# 2. Virtual Router with External Internet Gateway
resource "openstack_networking_router_v2" "vpc_router" {
name = "production-router"
external_network_id = data.openstack_networking_network_v2.public.id
}
resource "openstack_networking_router_interface_v2" "vpc_interface" {
router_id = openstack_networking_router_v2.vpc_router.id
subnet_id = okustera_network.vpc.subnet_id
}
# 3. Security Group for Web Servers
resource "okustera_security_group" "web_sg" {
name = "web-server-sg"
description = "Allow inbound HTTPS and SSH"
}
# Allow SSH from admin CIDR
resource "okustera_security_group_rule" "allow_ssh" {
security_group_id = okustera_security_group.web_sg.id
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 22
port_range_max = 22
remote_ip_prefix = "198.51.100.0/24"
}
# Allow HTTPS from all sources
resource "okustera_security_group_rule" "allow_https" {
security_group_id = okustera_security_group.web_sg.id
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 443
port_range_max = 443
remote_ip_prefix = "0.0.0.0/0"
}
# 4. Allocate and Associate Floating IP
resource "okustera_floating_ip" "web_fip" {
pool = "public_external"
}
resource "okustera_floating_ip_associate" "web_fip_assoc" {
floating_ip = okustera_floating_ip.web_fip.address
instance_id = okustera_compute_instance.web_server.id
}
Managing Networking via CLI
# List tenant networks
openstack network list
# List security groups
openstack security group list
# Create a security group rule for HTTP (Port 80)
openstack security group rule create \
--protocol tcp \
--dst-port 80:80 \
--remote-ip 0.0.0.0/0 \
--ingress \
web-server-sg
# Allocate a floating IP from the public pool
openstack floating ip create public_external
# Associate floating IP to a server
openstack server add floating ip web-server-01 198.51.100.45
REST API Reference
GET /api/v1/network/networks— List tenant private networks and subnets.POST /api/v1/network/networks— Create a new network with custom CIDR and DHCP.DELETE /api/v1/network/networks/{id}— Delete a private network.GET /api/v1/network/routers— List active virtual routers and gateway bindings.GET /api/v1/network/security-groups— List security groups and attached rules.POST /api/v1/network/security-groups— Create a new stateful security group.POST /api/v1/network/security-groups/{id}/rules— Add firewall rule (protocol, port range, CIDR).DELETE /api/v1/network/security-groups/rules/{rule_id}— Remove a firewall rule.GET /api/v1/network/floating-ips— List allocated floating IP addresses.POST /api/v1/network/floating-ips— Allocate a new public floating IP.POST /api/v1/network/floating-ips/{id}/associate— Bind public IP to instance port.POST /api/v1/network/floating-ips/{id}/disassociate— Unbind public IP from instance port.DELETE /api/v1/network/floating-ips/{id}— Release floating IP back to external pool.GET /api/v1/network/ports— List virtual network ports and IP configurations.